CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2017-18709

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R8300 before 1.0.2.94 and R8500 before 1.0.2.94.

    Published: 24 Apr 2020
    4.3
    Medium

    CVE-2017-18710

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects R8300 before 1.0.2.106 and R8500 before 1.0.2.106.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18711

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.28, R6400 before 1.01.32, R6400v2 before 1.0.2.44, R6700 before 1.0.1.36, R6900 before 1.0.1.34, R6900P before 1.3.0.8, R7000 before 1.0.9.14, R7000P before 1.3.0.8, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR4300v2 before 1.0.0.48, and WNDR4500v3 before 1.0.0.48.

    Published: 24 Apr 2020
    6.5
    Medium

    CVE-2017-18712

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D7800 before 1.0.1.28, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR4300v2 before 1.0.0.48, and WNDR4500v3 before 1.0.0.48.

    Published: 24 Apr 2020
    6.5
    Medium

    CVE-2017-18713

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects D7800 before 1.0.1.28, R6700 before 1.0.1.36, R6900 before 1.0.1.34, R7500v2 before 1.0.3.20, R7800 before 1.0.2.40, R9000 before 1.0.2.52, WNDR4300v2 before 1.0.0.48, and WNDR4500v3 before 1.0.0.48.

    Published: 24 Apr 2020
    6.5
    Medium

    CVE-2017-18714

    Last Modified: 21 Nov 2024

    NETGEAR WNDR4500v3 devices before 1.0.0.48 are affected by denial of service.

    Published: 24 Apr 2020
    6.1
    Medium

    CVE-2017-18715

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by reflected XSS. This affects EX3700 before 1.0.0.66, EX3800 before 1.0.0.66, EX6100 before 1.0.2.20, EX6120 before 1.0.0.34, EX6150 before 1.0.0.36, EX6200 before 1.0.3.84, and EX7000 before 1.0.0.60.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18716

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18717

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18718

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18719

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6020 before 1.1.00.26, R6080 before 1.1.00.26; R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.1
    High

    CVE-2020-5870

    Last Modified: 21 Nov 2024

    In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18720

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by authentication bypass. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18721

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18722

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18723

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18724

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18725

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24. R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18726

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects R6020 before 1.0.0.30, R6080 before 1.0.0.30, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    9.1
    Critical

    CVE-2020-5869

    Last Modified: 21 Nov 2024

    In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18727

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18728

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18729

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6020 before 1.0.0.30, R6080 before 1.0.0.30, R6120 before 1.0.0.36, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    9.8
    Critical

    CVE-2020-5868

    Last Modified: 21 Nov 2024

    In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems using HTTP requests to the BIG-IQ user interface.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18730

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects D6200 before 1.1.00.24, R6020 before 1.0.0.30, R6080 before 1.0.0.30, R6120 before 1.0.0.36, R6700v2 before 1.1.0.42, R6800 before 1.1.0.42, and R6900v2 before 1.1.0.42.

    Published: 24 Apr 2020
    8.8
    High

    CVE-2017-18731

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects R6100 before 1.0.1.16, R7500 before 1.0.0.112, R7500v2 before 1.0.3.20, R7800 before 1.0.2.36, and WNR2000v5 before 1.0.0.58.

    Published: 24 Apr 2020
    9.8
    Critical

    CVE-2020-12134

    Last Modified: 21 Nov 2024

    Nanometrics Centaur through 4.3.23 and TitanSMA through 4.2.20 mishandle access control for the syslog log.

    Published: 24 Apr 2020
    5.3
    Medium

    CVE-2020-12063

    Last Modified: 21 Nov 2024

    A certain Postfix 2.10.1-7 package could allow an attacker to send an email from an arbitrary-looking sender via a homoglyph attack, as demonstrated by the similarity of \xce\xbf to the 'o' character. This is potentially relevant when the /etc/postfix/sender_login feature is used, because a spoofed outbound message that uses a configured sender address is blocked with a "Sender address rejected: not logged in" error message, but a spoofed outbound message that uses a homoglyph of a configured sender address is not blocked. NOTE: some third parties argue that any missed blocking of spoofed outbound messages - except for exact matches to a sender address in the /etc/postfix/sender_login file - is outside the design goals of Postfix and thus cannot be considered a Postfix vulnerability

    Published: 24 Apr 2020
    6.5
    Medium

    CVE-2020-7923

    Last Modified: 21 Nov 2024

    A user authorized to perform database queries may cause denial of service by issuing specially crafted queries, which violate an invariant in the query subsystem's support for geoNear. This issue affects MongoDB Server v4.4 versions prior to 4.4.0-rc7; MongoDB Server v4.2 versions prior to 4.2.8 and MongoDB Server v4.0 versions prior to 4.0.19.

    Published: 24 Apr 2020
    5.5
    Medium

    CVE-2020-9489

    Last Modified: 21 Nov 2024

    A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser were partially fixed by upgrading the com.googlecode:isoparser:1.1.22 dependency to org.tallison:isoparser:1.9.41.2. For unrelated security reasons, we upgraded org.apache.cxf to 3.3.6 as part of the 1.24.1 release.

    Published: 24 Apr 2020
    6.5
    Medium

    CVE-2019-15793

    Last Modified: 21 Nov 2024

    In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, whereas they should have been translated into the s_user_ns for the lower filesystem. This resulted in using ids other than the intended ones in the lower fs, which likely did not map into the shifts s_user_ns. A local attacker could use this to possibly bypass discretionary access control permissions.

    Published: 23 Apr 2020
    7.1
    High

    CVE-2019-15792

    Last Modified: 21 Nov 2024

    In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() calls fdget(oldfd), then without further checks passes the resulting file* into shiftfs_real_fdget(), which casts file->private_data, a void* that points to a filesystem-dependent type, to a "struct shiftfs_file_info *". As the private_data is not required to be a pointer, an attacker can use this to cause a denial of service or possibly execute arbitrary code.

    Published: 23 Apr 2020
    6.1
    Medium

    CVE-2020-12132

    Last Modified: 21 Nov 2024

    Fifthplay S.A.M.I before 2019.3_HP2 allows unauthenticated stored XSS via a POST request.

    Published: 23 Apr 2020
    6.1
    Medium

    CVE-2020-12129

    Last Modified: 21 Nov 2024

    The AirDisk Pro app 5.5.3 for iOS allows XSS via the createFolder parameter of the Create Folder function.

    Published: 23 Apr 2020
    6.1
    Medium

    CVE-2020-12130

    Last Modified: 21 Nov 2024

    The AirDisk Pro app 5.5.3 for iOS allows XSS via the deleteFile parameter of the Delete function.

    Published: 23 Apr 2020
    6.1
    Medium

    CVE-2020-12131

    Last Modified: 21 Nov 2024

    The AirDisk Pro app 5.5.3 for iOS allows XSS via the devicename parameter (shown next to the UI logo).

    Published: 23 Apr 2020
    7.5
    High

    CVE-2020-12128

    Last Modified: 21 Nov 2024

    DONG JOO CHO File Transfer iFamily 2.1 allows directory traversal related to the ./etc/ path.

    Published: 23 Apr 2020
    9.3
    Critical

    CVE-2020-11012

    Last Modified: 21 Nov 2024

    MinIO versions before RELEASE.2020-04-23T00-58-49Z have an authentication bypass issue in the MinIO admin API. Given an admin access key, it is possible to perform admin API operations i.e. creating new service accounts for existing access keys - without knowing the admin secret key. This has been fixed and released in version RELEASE.2020-04-23T00-58-49Z.

    Published: 23 Apr 2020
    4.9
    Medium

    CVE-2018-21166

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by denial of service. This affects R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.54, WNDR4500v3 before 1.0.0.54, and WNR2000v5 before 1.0.0.64.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2018-21160

    Last Modified: 21 Nov 2024

    NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.

    Published: 23 Apr 2020
    8.2
    High

    CVE-2020-12118

    Last Modified: 21 Nov 2024

    The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties.

    Published: 23 Apr 2020
    4.9
    Medium

    CVE-2018-21165

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by denial of service. This affects R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.54, WNDR4500v3 before 1.0.0.54, and WNR2000v5 before 1.0.0.64.

    Published: 23 Apr 2020
    7.2
    High

    CVE-2018-21164

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.64 and WNDR3700v5 before 1.1.0.54.

    Published: 23 Apr 2020
    7.2
    High

    CVE-2018-21163

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a stack-based buffer overflow by an authenticated user. This affects DGN2200Bv4 before 1.0.0.102, DGN2200v4 before 1.0.0.102, EX3700 before 1.0.0.70, EX3800 before 1.0.0.70, EX6000 before 1.0.0.30, EX6100 before 1.0.2.22, EX6120 before 1.0.0.40, EX6130 before 1.0.0.22, EX6150 before 1.0.0.38, EX6200 before 1.0.3.86, EX7000 before 1.0.0.64, R6300v2 before 1.0.4.22, R6900P before 1.3.0.18, R7000P before 1.3.0.18, R7300DST before 1.0.0.62, R7900P before 1.3.0.10, R8000 before 1.0.4.12, R8000P before 1.3.0.10, WN2500RPv2 before 1.0.1.52, and WNDR3400v3 before 1.0.1.18.

    Published: 23 Apr 2020
    9.8
    Critical

    CVE-2018-21162

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.0.78, EX6200 before 1.0.3.86, EX7000 before 1.0.0.64, R6250 before 1.0.4.8, R6300v2 before 1.0.4.6, R6400 before 1.0.1.12, R6700 before 1.0.1.16, R7000 before 1.0.7.10, R7100LG before 1.0.0.42, R7300DST before 1.0.0.44, R7900 before 1.0.1.12, R8000 before 1.0.3.36, R8300 before 1.0.2.74, R8500 before 1.0.2.74, WNDR3400v3 before 1.0.1.14, and WNR3500Lv2 before 1.2.0.48.

    Published: 23 Apr 2020
    9.8
    Critical

    CVE-2018-21161

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.34, R7800 before 1.0.2.46, and R9000 before 1.0.3.16.

    Published: 23 Apr 2020
    4.9
    Medium

    CVE-2018-21142

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by denial of service. This affects R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7800 before 1.0.2.42, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.54, WNDR4500v3 before 1.0.0.54, and WNR2000v5 before 1.0.0.64.

    Published: 23 Apr 2020
    7.5
    High

    CVE-2018-21139

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by disclosure of sensitive information. This affects D1500 before 1.0.0.27, D500 before 1.0.0.27, D6100 before 1.0.0.58, D6200 before 1.1.00.30, D6220 before 1.0.0.46, D6400 before 1.0.0.82, D7000 before 1.0.1.68, D7000v2 before 1.0.0.51, D7800 before 1.0.1.42, D8500 before 1.0.3.42, DC112A before 1.0.0.40, DGN2200Bv4 before 1.0.0.102, DGN2200v4 before 1.0.0.102, JNR1010v2 before 1.1.0.54, JR6150 before 1.0.1.18, JWNR2010v5 before 1.1.0.54, PR2000 before 1.0.0.24, R6020 before 1.0.0.34, R6050 before 1.0.1.18, R6080 before 1.0.0.34, R6100 before 1.0.1.22, R6120 before 1.0.0.42, R6220 before 1.1.0.68, R6250 before 1.0.4.30, R6300v2 before 1.0.4.32, R6400 before 1.0.1.44, R6400v2 before 1.0.2.60, R6700 before 1.0.1.48, R6700v2 before 1.2.0.24, R6800 before 1.2.0.24, R6900 before 1.0.1.48, R6900P before 1.3.1.44, R6900v2 before 1.2.0.24, R7000 before 1.0.9.34, R7000P before 1.3.1.44, R7100LG before 1.0.0.48, R7300 before 1.0.0.68, R7500 before 1.0.0.124, R7500v2 before 1.0.3.38, R7900 before 1.0.2.16, R7900P before 1.4.1.24, R8000 before 1.0.4.18, R8000P before 1.4.1.24, R8300 before 1.0.2.122, R8500 before 1.0.2.122, WN3000RP before 1.0.0.68, WN3000RPv2 before 1.0.0.68, WNDR3400v3 before 1.0.1.18, WNDR3700v4 before 1.0.2.102, WNDR3700v5 before 1.1.0.54, WNDR4300v1 before 1.0.2.104, WNDR4300v2 before 1.0.0.56, WNDR4500v3 before 1.0.0.56, WNR1000v4 before 1.1.0.54, WNR2020 before 1.1.0.54, WNR2050 before 1.1.0.54, and WNR3500Lv2 before 1.2.0.54.

    Published: 23 Apr 2020
    8.8
    High

    CVE-2018-21138

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D3600 before 1.0.0.76 and D6000 before 1.0.0.76.

    Published: 23 Apr 2020
    9.8
    Critical

    CVE-2018-21137

    Last Modified: 21 Nov 2024

    Certain NETGEAR devices are affected by a hardcoded password. This affects D3600 before 1.0.0.76 and D6000 before 1.0.0.76.

    Published: 23 Apr 2020