Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2015-8367 | The phase_one_correct function in Libraw before 0.17.1 allows attackers to cause memory errors and possibly execute arb… | Critical (9.8) | 2020-01-14 | Environment Specific |
| CVE-2014-5138 | Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple insta… | High (7.5) | 2020-01-14 | Environment Specific |
| CVE-2019-0219 | A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's w… | Critical (9.8) | 2020-01-14 | Environment Specific |
| CVE-2013-2773 | Nitro PDF 8.5.0.26: A specially crafted DLL file can facilitate Arbitrary Code Execution | High (7.8) | 2020-01-14 | Environment Specific |
| CVE-2020-6955 | An issue was discovered on Cayin SMP-PRO4 devices. They allow image_preview.html?filename= reflected XSS. | Medium (6.1) | 2020-01-13 | Environment Specific |