Search
Find a vulnerability
Search criteria
24 vulnerabilities by sharp
CVE-2024-36254 (GCVE-0-2024-36254)
Vulnerability from nvd – Published: 2024-11-26 07:38 – Updated: 2024-11-26 14:48
VLAI
EPSS
VEX
Summary
Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.
Severity
7.5 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-26 14:24 UTC
CWE
- CWE-125 - Out-of-bounds read
Assigner
References
Impacted products
51 products
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | Multiple MFPs (multifunction printers) |
Affected:
See the information provided by Sharp Corporation listed under [References]
|
|
| Toshiba Tec Corporation | Multiple MFPs (multifunction printers) |
Affected:
See the information provided by Toshiba Tec Corporation listed under [References]
|
|
| sharp | bp-90c70 |
Affected:
0 , ≤ 200
(custom)
cpe:2.3:h:sharp:bp-90c70:-:*:*:*:*:*:*:* |
|
| sharp | bp-90c80 |
Affected:
0 , ≤ 200
(custom)
cpe:2.3:h:sharp:bp-90c80:-:*:*:*:*:*:*:* |
|
| sharp | bp-70c65 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-70c65:-:*:*:*:*:*:*:* |
|
| sharp | bp-70c55 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-70c55:-:*:*:*:*:*:*:* |
|
| sharp | bp-70c45 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-70c45:-:*:*:*:*:*:*:* |
|
| sharp | bp-70c36 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-70c36:-:*:*:*:*:*:*:* |
|
| sharp | bp-70c31 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-70c31:-:*:*:*:*:*:*:* |
|
| sharp | bp-60c45 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-60c45:-:*:*:*:*:*:*:* |
|
| sharp | bp-60c36 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-60c36:-:*:*:*:*:*:*:* |
|
| sharp | bp-60c31 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-60c31:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c65 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c65:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c55 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c55:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c45 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c45:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c36 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c36:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c31 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c31:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c26 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c26:-:*:*:*:*:*:*:* |
|
| sharp | bp-55c26 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-55c26:-:*:*:*:*:*:*:* |
|
| sharp | mx-8081 |
Affected:
0 , ≤ 150
(custom)
cpe:2.3:h:sharp:mx-8081:-:*:*:*:*:*:*:* |
|
| sharp | mx-7081 |
Affected:
0 , ≤ 150
(custom)
cpe:2.3:h:sharp:mx-7081:-:*:*:*:*:*:*:* |
|
| sharp | mx-6071 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-6071:-:*:*:*:*:*:*:* |
|
| sharp | mx-5071 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-5071:-:*:*:*:*:*:*:* |
|
| sharp | mx-4071 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-4071:-:*:*:*:*:*:*:* |
|
| sharp | mx-3571 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3571:-:*:*:*:*:*:*:* |
|
| sharp | mx-3071 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3071:-:*:*:*:*:*:*:* |
|
| sharp | mx-4061 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-4061:-:*:*:*:*:*:*:* |
|
| sharp | mx-3561 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3561:-:*:*:*:*:*:*:* |
|
| sharp | mx-3061 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3061:-:*:*:*:*:*:*:* |
|
| sharp | mx-6051 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-6051:-:*:*:*:*:*:*:* |
|
| sharp | mx-5051 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-5051:-:*:*:*:*:*:*:* |
|
| sharp | mx-4051 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-4051:-:*:*:*:*:*:*:* |
|
| sharp | mx-3551 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3551:-:*:*:*:*:*:*:* |
|
| sharp | mx-3051 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3051:-:*:*:*:*:*:*:* |
|
| sharp | mx-2651 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-2651:-:*:*:*:*:*:*:* |
|
| sharp | mx-6071s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-6071s:-:*:*:*:*:*:*:* |
|
| sharp | mx-5071s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-5071s:-:*:*:*:*:*:*:* |
|
| sharp | mx-4071s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-4071s:-:*:*:*:*:*:*:* |
|
| sharp | mx-3571s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3571s:-:*:*:*:*:*:*:* |
|
| sharp | mx-3071s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3071s:-:*:*:*:*:*:*:* |
|
| sharp | mx-4061s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-4061s:-:*:*:*:*:*:*:* |
|
| sharp | mx-3561s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3561s:-:*:*:*:*:*:*:* |
|
| sharp | mx-3061s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3061s:-:*:*:*:*:*:*:* |
|
| sharp | bp-30c25 |
Affected:
0 , ≤ 123
(custom)
cpe:2.3:h:sharp:bp-30c25:-:*:*:*:*:*:*:* |
|
| sharp | bp-30c25y |
Affected:
0 , ≤ 123
(custom)
cpe:2.3:h:sharp:bp-30c25y:-:*:*:*:*:*:*:* |
|
| sharp | bp-30c25z |
Affected:
0 , ≤ 123
(custom)
cpe:2.3:h:sharp:bp-30c25z:-:*:*:*:*:*:*:* |
|
| sharp | bp-30c25t |
Affected:
0 , ≤ 123
(custom)
cpe:2.3:h:sharp:bp-30c25t:-:*:*:*:*:*:*:* |
|
| sharp | mx-7580n |
Affected:
0 , ≤ 502
(custom)
cpe:2.3:h:sharp:mx-7580n:-:*:*:*:*:*:*:* |
|
| sharp | mx-6580n |
Affected:
0 , ≤ 502
(custom)
cpe:2.3:h:sharp:mx-6580n:-:*:*:*:*:*:*:* |
|
| sharp | mx-8090n |
Affected:
0 , ≤ 404
(custom)
cpe:2.3:h:sharp:mx-8090n:-:*:*:*:*:*:*:* |
|
| sharp | mx-7090n |
Affected:
0 , ≤ 404
(custom)
cpe:2.3:h:sharp:mx-7090n:-:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:h:sharp:bp-90c70:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-90c70",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "200",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-90c80:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-90c80",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "200",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-70c65:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-70c65",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-70c55:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-70c55",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-70c45:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-70c45",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-70c36:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-70c36",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-70c31:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-70c31",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-60c45:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-60c45",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-60c36:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-60c36",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-60c31:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-60c31",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c65:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c65",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c55:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c55",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c45:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c45",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c36:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c36",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c31:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c31",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c26:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c26",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-55c26:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-55c26",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-8081:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-8081",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "150",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-7081:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-7081",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "150",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-6071:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-6071",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-5071:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-5071",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-4071:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-4071",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3571:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3571",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3071:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3071",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-4061:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-4061",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3561:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3561",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3061:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3061",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-6051:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-6051",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-5051:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-5051",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-4051:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-4051",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3551:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3551",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3051:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3051",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-2651:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-2651",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-6071s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-6071s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-5071s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-5071s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-4071s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-4071s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3571s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3571s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3071s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3071s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-4061s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-4061s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3561s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3561s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3061s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3061s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-30c25:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-30c25",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "123",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-30c25y:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-30c25y",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "123",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-30c25z:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-30c25z",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "123",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-30c25t:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-30c25t",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "123",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-7580n:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-7580n",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "502",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-6580n:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-6580n",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "502",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-8090n:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-8090n",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "404",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-7090n:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-7090n",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "404",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-36254",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-26T14:24:25.876189Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-26T14:48:35.480Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Multiple MFPs (multifunction printers)",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "See the information provided by Sharp Corporation listed under [References]"
}
]
},
{
"product": "Multiple MFPs (multifunction printers)",
"vendor": "Toshiba Tec Corporation",
"versions": [
{
"status": "affected",
"version": "See the information provided by Toshiba Tec Corporation listed under [References]"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-125",
"description": "Out-of-bounds read",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-26T07:38:30.408Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://global.sharp/products/copier/info/info_security_2024-05.html"
},
{
"url": "https://jp.sharp/business/print/information/info_security_2024-05.html"
},
{
"url": "https://www.toshibatec.com/information/20240531_02.html"
},
{
"url": "https://www.toshibatec.co.jp/information/20240531_02.html"
},
{
"url": "https://jvn.jp/en/vu/JVNVU93051062/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2024-36254",
"datePublished": "2024-11-26T07:38:30.408Z",
"dateReserved": "2024-05-22T09:00:17.089Z",
"dateUpdated": "2024-11-26T14:48:35.480Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-36251 (GCVE-0-2024-36251)
Vulnerability from nvd – Published: 2024-11-26 07:38 – Updated: 2025-11-04 17:21
VLAI
EPSS
VEX
Summary
The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed properly and device-crash happens. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Severity
7.5 (High)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-26 16:19 UTC
CWE
- CWE-125 - Out-of-bounds read
Assigner
References
7 references
Impacted products
24 products
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | Multiple MFPs (multifunction printers) |
Affected:
See the information provided by Sharp Corporation listed under [References]
|
|
| Toshiba Tec Corporation | Multiple MFPs (multifunction printers) |
Affected:
See the information provided by Toshiba Tec Corporation listed under [References]
|
|
| sharp | mx-m905 |
Affected:
611
cpe:2.3:h:sharp:mx-m905:-:*:*:*:*:*:*:* |
|
| sharp | mx-m6070 |
Affected:
502
cpe:2.3:h:sharp:mx-m6070:-:*:*:*:*:*:*:* |
|
| sharp | mx-m5070 |
Affected:
502
cpe:2.3:h:sharp:mx-m5070:-:*:*:*:*:*:*:* |
|
| sharp | mx-m4070 |
Affected:
502
cpe:2.3:h:sharp:mx-m4070:-:*:*:*:*:*:*:* |
|
| sharp | mx-m3570 |
Affected:
502
cpe:2.3:h:sharp:mx-m3570:-:*:*:*:*:*:*:* |
|
| sharp | mx-m3070 |
Affected:
502
cpe:2.3:h:sharp:mx-m3070:-:*:*:*:*:*:*:* |
|
| sharp | mx-m6050 |
Affected:
502
cpe:2.3:h:sharp:mx-m6050:-:*:*:*:*:*:*:* |
|
| sharp | mx-m5050 |
Affected:
502
cpe:2.3:h:sharp:mx-m5050:-:*:*:*:*:*:*:* |
|
| sharp | mx-m4050 |
Affected:
502
cpe:2.3:h:sharp:mx-m4050:-:*:*:*:*:*:*:* |
|
| sharp | mx-m3550 |
Affected:
502
cpe:2.3:h:sharp:mx-m3550:-:*:*:*:*:*:*:* |
|
| sharp | mx-m3050 |
Affected:
502
cpe:2.3:h:sharp:mx-m3050:-:*:*:*:*:*:*:* |
|
| sharp | mx-m2630 |
Affected:
502
cpe:2.3:h:sharp:mx-m2630:-:*:*:*:*:*:*:* |
|
| sharp | bp-b550wd |
Affected:
250
cpe:2.3:h:sharp:bp-b550wd:-:*:*:*:*:*:*:* |
|
| sharp | bp-b540wr |
Affected:
250
cpe:2.3:h:sharp:bp-b540wr:-:*:*:*:*:*:*:* |
|
| sharp | bp-b547wd |
Affected:
250
cpe:2.3:h:sharp:bp-b547wd:-:*:*:*:*:*:*:* |
|
| sharp | bp-b537wr |
Affected:
250
cpe:2.3:h:sharp:bp-b537wr:-:*:*:*:*:*:*:* |
|
| sharp | mx-b455w |
Affected:
404
cpe:2.3:h:sharp:mx-b455w:-:*:*:*:*:*:*:* |
|
| sharp | mx-b355w |
Affected:
404
cpe:2.3:h:sharp:mx-b355w:-:*:*:*:*:*:*:* |
|
| sharp | mx-b455wz |
Affected:
404
cpe:2.3:h:sharp:mx-b455wz:-:*:*:*:*:*:*:* |
|
| sharp | mx-b355wz |
Affected:
404
cpe:2.3:h:sharp:mx-b355wz:-:*:*:*:*:*:*:* |
|
| sharp | mx-b455wt |
Affected:
404
cpe:2.3:h:sharp:mx-b455wt:-:*:*:*:*:*:*:* |
|
| sharp | mx-b355wt |
Affected:
404
cpe:2.3:h:sharp:mx-b355wt:-:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:h:sharp:mx-m905:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m905",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "611"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m6070:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m6070",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m5070:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m5070",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m4070:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m4070",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m3570:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m3570",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m3070:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m3070",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m6050:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m6050",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m5050:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m5050",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m4050:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m4050",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m3550:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m3550",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m3050:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m3050",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m2630:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m2630",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m6070:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m6070",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-b550wd:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-b550wd",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "250"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-b540wr:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-b540wr",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "250"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-b547wd:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-b547wd",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "250"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-b537wr:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-b537wr",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "250"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b455w:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b455w",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b355w:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b355w",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b455wz:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b455wz",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b355wz:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b355wz",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b455wt:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b455wt",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b355wt:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b355wt",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-36251",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-26T16:19:13.648769Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-26T16:28:15.625Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2025-11-04T17:21:07.405Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://seclists.org/fulldisclosure/2024/Jul/0"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Multiple MFPs (multifunction printers)",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "See the information provided by Sharp Corporation listed under [References]"
}
]
},
{
"product": "Multiple MFPs (multifunction printers)",
"vendor": "Toshiba Tec Corporation",
"versions": [
{
"status": "affected",
"version": "See the information provided by Toshiba Tec Corporation listed under [References]"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed properly and device-crash happens. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-125",
"description": "Out-of-bounds read",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-26T07:38:24.464Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://global.sharp/products/copier/info/info_security_2024-05.html"
},
{
"url": "https://jp.sharp/business/print/information/info_security_2024-05.html"
},
{
"url": "https://www.toshibatec.com/information/20240531_02.html"
},
{
"url": "https://www.toshibatec.co.jp/information/20240531_02.html"
},
{
"url": "https://jvn.jp/en/vu/JVNVU93051062/"
},
{
"url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2024-36251",
"datePublished": "2024-11-26T07:38:24.464Z",
"dateReserved": "2024-05-22T09:00:10.181Z",
"dateUpdated": "2025-11-04T17:21:07.405Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2023-38290 (GCVE-0-2023-38290)
Vulnerability from nvd – Published: 2024-04-22 00:00 – Updated: 2024-08-02 17:39
VLAI
EPSS
VEX
Summary
Certain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with a package name of com.evenwell.fqc (versionCode='9020801', versionName='9.0208.01' ; versionCode='9020913', versionName='9.0209.13' ; versionCode='9021203', versionName='9.0212.03') that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to inadequate access control. No permissions or special privileges are necessary to exploit the vulnerability in the com.evenwell.fqc app. No user interaction is required beyond installing and running a third-party app. The vulnerability allows local apps to access sensitive functionality that is generally restricted to pre-installed apps, such as programmatically performing the following actions: granting arbitrary permissions (which can be used to obtain sensitive user data), installing arbitrary apps, video recording the screen, wiping the device (removing the user's apps and data), injecting arbitrary input events, calling emergency phone numbers, disabling apps, accessing notifications, and much more. The software build fingerprints for each confirmed vulnerable device are as follows: BLU View 2 (BLU/B131DL/B130DL:11/RP1A.200720.011/1672046950:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1663816427:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1656476696:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1647856638:user/release-keys) and Sharp Rouvo V (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_460:user/release-keys and SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys). This malicious app starts an exported activity named com.evenwell.fqc/.activity.ClickTest, crashes the com.evenwell.fqc app by sending an empty Intent (i.e., having not extras) to the com.evenwell.fqc/.FQCBroadcastReceiver receiver component, and then it sends command arbitrary shell commands to the com.evenwell.fqc/.FQCService service component which executes them with "system" privileges.
Severity
7.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-05-01 18:49 UTC
CWE
- n/a
- CWE-1263 - Improper Physical Access Control
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:bluview:bluview:2:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bluview",
"vendor": "bluview",
"versions": [
{
"status": "affected",
"version": "2"
}
]
},
{
"cpes": [
"cpe:2.3:a:sharp:rouvo_v:android_10:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "rouvo_v",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "Android 10"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2023-38290",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-01T18:49:30.272312Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1263",
"description": "CWE-1263 Improper Physical Access Control",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T17:28:22.588Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T17:39:12.068Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://media.defcon.org/DEF%20CON%2031/DEF%20CON%2031%20presentations/Ryan%20Johnson%20Mohamed%20Elsabagh%20Angelos%20Stavrou%20-%20Still%20Vulnerable%20Out%20of%20the%20Box%20Revisiting%20the%20Security%20of%20Prepaid%20Android%20Carrier%20Devices.pdf"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with a package name of com.evenwell.fqc (versionCode=\u00279020801\u0027, versionName=\u00279.0208.01\u0027 ; versionCode=\u00279020913\u0027, versionName=\u00279.0209.13\u0027 ; versionCode=\u00279021203\u0027, versionName=\u00279.0212.03\u0027) that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to inadequate access control. No permissions or special privileges are necessary to exploit the vulnerability in the com.evenwell.fqc app. No user interaction is required beyond installing and running a third-party app. The vulnerability allows local apps to access sensitive functionality that is generally restricted to pre-installed apps, such as programmatically performing the following actions: granting arbitrary permissions (which can be used to obtain sensitive user data), installing arbitrary apps, video recording the screen, wiping the device (removing the user\u0027s apps and data), injecting arbitrary input events, calling emergency phone numbers, disabling apps, accessing notifications, and much more. The software build fingerprints for each confirmed vulnerable device are as follows: BLU View 2 (BLU/B131DL/B130DL:11/RP1A.200720.011/1672046950:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1663816427:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1656476696:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1647856638:user/release-keys) and Sharp Rouvo V (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_460:user/release-keys and SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys). This malicious app starts an exported activity named com.evenwell.fqc/.activity.ClickTest, crashes the com.evenwell.fqc app by sending an empty Intent (i.e., having not extras) to the com.evenwell.fqc/.FQCBroadcastReceiver receiver component, and then it sends command arbitrary shell commands to the com.evenwell.fqc/.FQCService service component which executes them with \"system\" privileges."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-04-22T14:55:40.228Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://media.defcon.org/DEF%20CON%2031/DEF%20CON%2031%20presentations/Ryan%20Johnson%20Mohamed%20Elsabagh%20Angelos%20Stavrou%20-%20Still%20Vulnerable%20Out%20of%20the%20Box%20Revisiting%20the%20Security%20of%20Prepaid%20Android%20Carrier%20Devices.pdf"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2023-38290",
"datePublished": "2024-04-22T00:00:00.000Z",
"dateReserved": "2023-07-14T00:00:00.000Z",
"dateUpdated": "2024-08-02T17:39:12.068Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2192 (GCVE-0-2017-2192)
Vulnerability from nvd – Published: 2017-06-09 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in RW-5100 tool to verify execution environment for Windows 7 version 1.1.0.0 and RW-5100 tool to verify execution environment for Windows 8.1 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/99290 | vdb-entryx_refsource_BID |
| http://jvn.jp/en/jp/JVN51274854/index.html | third-party-advisoryx_refsource_JVN |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | RW-5100 tool to verify execution environment for Windows 7 |
Affected:
version 1.1.0.0
|
|
| Sharp Corporation | RW-5100 tool to verify execution environment for Windows 8.1 |
Affected:
version 1.2.0.0
|
Date Public
2017-06-01 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:03.652Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "RW-5100 tool to verify execution environment for Windows 7",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 1.1.0.0"
}
]
},
{
"product": "RW-5100 tool to verify execution environment for Windows 8.1",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 1.2.0.0"
}
]
}
],
"datePublic": "2017-06-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in RW-5100 tool to verify execution environment for Windows 7 version 1.1.0.0 and RW-5100 tool to verify execution environment for Windows 8.1 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-06-28T09:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2192",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "RW-5100 tool to verify execution environment for Windows 7",
"version": {
"version_data": [
{
"version_value": "version 1.1.0.0"
}
]
}
},
{
"product_name": "RW-5100 tool to verify execution environment for Windows 8.1",
"version": {
"version_data": [
{
"version_value": "version 1.2.0.0"
}
]
}
}
]
},
"vendor_name": "Sharp Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in RW-5100 tool to verify execution environment for Windows 7 version 1.1.0.0 and RW-5100 tool to verify execution environment for Windows 8.1 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "99290",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2192",
"datePublished": "2017-06-09T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:03.652Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2191 (GCVE-0-2017-2191)
Vulnerability from nvd – Published: 2017-06-09 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/99290 | vdb-entryx_refsource_BID |
| http://jvn.jp/en/jp/JVN51274854/index.html | third-party-advisoryx_refsource_JVN |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | RW-5100 driver installer for Windows 7 |
Affected:
version 1.0.0.9
|
|
| Sharp Corporation | RW-5100 driver installer for Windows 8.1 |
Affected:
version 1.0.1.0
|
Date Public
2017-06-01 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:03.670Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "RW-5100 driver installer for Windows 7",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 1.0.0.9"
}
]
},
{
"product": "RW-5100 driver installer for Windows 8.1",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 1.0.1.0"
}
]
}
],
"datePublic": "2017-06-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-06-28T09:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2191",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "RW-5100 driver installer for Windows 7",
"version": {
"version_data": [
{
"version_value": "version 1.0.0.9"
}
]
}
},
{
"product_name": "RW-5100 driver installer for Windows 8.1",
"version": {
"version_data": [
{
"version_value": "version 1.0.1.0"
}
]
}
}
]
},
"vendor_name": "Sharp Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "99290",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2191",
"datePublished": "2017-06-09T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:03.670Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2190 (GCVE-0-2017-2190)
Vulnerability from nvd – Published: 2017-06-09 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in RW-4040 tool to verify execution environment for Windows 7 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/99290 | vdb-entryx_refsource_BID |
| http://jvn.jp/en/jp/JVN51274854/index.html | third-party-advisoryx_refsource_JVN |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | RW-4040 tool to verify execution environment for Windows 7 |
Affected:
version 1.2.0.0
|
Date Public
2017-06-01 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:04.327Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "RW-4040 tool to verify execution environment for Windows 7",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 1.2.0.0"
}
]
}
],
"datePublic": "2017-06-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in RW-4040 tool to verify execution environment for Windows 7 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-06-28T09:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2190",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "RW-4040 tool to verify execution environment for Windows 7",
"version": {
"version_data": [
{
"version_value": "version 1.2.0.0"
}
]
}
}
]
},
"vendor_name": "Sharp Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in RW-4040 tool to verify execution environment for Windows 7 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "99290",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2190",
"datePublished": "2017-06-09T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:04.327Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2189 (GCVE-0-2017-2189)
Vulnerability from nvd – Published: 2017-06-09 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in RW-4040 driver installer for Windows 7 version 2.27 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/99290 | vdb-entryx_refsource_BID |
| http://jvn.jp/en/jp/JVN51274854/index.html | third-party-advisoryx_refsource_JVN |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | RW-4040 driver installer for Windows 7 |
Affected:
version 2.27
|
Date Public
2017-06-01 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:04.163Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "RW-4040 driver installer for Windows 7",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 2.27"
}
]
}
],
"datePublic": "2017-06-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in RW-4040 driver installer for Windows 7 version 2.27 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-06-28T09:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2189",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "RW-4040 driver installer for Windows 7",
"version": {
"version_data": [
{
"version_value": "version 2.27"
}
]
}
}
]
},
"vendor_name": "Sharp Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in RW-4040 driver installer for Windows 7 version 2.27 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "99290",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2189",
"datePublished": "2017-06-09T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:04.163Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2016-1176 (GCVE-0-2016-1176)
Vulnerability from nvd – Published: 2016-04-05 14:00 – Updated: 2024-08-05 22:48
VLAI
EPSS
VEX
Summary
Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://jvndb.jvn.jp/jvndb/JVNDB-2016-000038 | third-party-advisoryx_refsource_JVNDB |
| http://jvn.jp/en/jp/JVN41875357/index.html | third-party-advisoryx_refsource_JVN |
Date Public
2016-04-04 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T22:48:13.259Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVNDB-2016-000038",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000038"
},
{
"name": "JVN#41875357",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN41875357/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2016-04-04T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2016-04-05T14:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVNDB-2016-000038",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000038"
},
{
"name": "JVN#41875357",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN41875357/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2016-1176",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVNDB-2016-000038",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000038"
},
{
"name": "JVN#41875357",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN41875357/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2016-1176",
"datePublished": "2016-04-05T14:00:00.000Z",
"dateReserved": "2015-12-26T00:00:00.000Z",
"dateUpdated": "2024-08-05T22:48:13.259Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2016-1175 (GCVE-0-2016-1175)
Vulnerability from nvd – Published: 2016-04-05 14:00 – Updated: 2024-08-05 22:48
VLAI
EPSS
VEX
Summary
Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://jvn.jp/en/jp/JVN47164236/index.html | third-party-advisoryx_refsource_JVN |
| http://jvndb.jvn.jp/jvndb/JVNDB-2016-000039 | third-party-advisoryx_refsource_JVNDB |
| http://www.sharp.co.jp/support/photoplayer/fw_upd… | x_refsource_CONFIRM |
Date Public
2016-04-04 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T22:48:13.087Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVN#47164236",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN47164236/index.html"
},
{
"name": "JVNDB-2016-000039",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000039"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2016-04-04T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2016-04-05T14:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVN#47164236",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN47164236/index.html"
},
{
"name": "JVNDB-2016-000039",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000039"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2016-1175",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVN#47164236",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN47164236/index.html"
},
{
"name": "JVNDB-2016-000039",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000039"
},
{
"name": "http://www.sharp.co.jp/support/photoplayer/fw_update.html",
"refsource": "CONFIRM",
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2016-1175",
"datePublished": "2016-04-05T14:00:00.000Z",
"dateReserved": "2015-12-26T00:00:00.000Z",
"dateUpdated": "2024-08-05T22:48:13.087Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2014-7252 (GCVE-0-2014-7252)
Vulnerability from nvd – Published: 2014-12-05 17:00 – Updated: 2024-08-06 12:40
VLAI
EPSS
VEX
Summary
Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets 102SH allow local users to execute arbitrary code or read kernel memory via unknown vectors related to userland data and "improper data validation."
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
4 references
| URL | Tags |
|---|---|
| http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-0… | third-party-advisoryx_refsource_JVNDB |
| http://jvn.jp/en/jp/JVN67792023/index.html | third-party-advisoryx_refsource_JVN |
| http://jvn.jp/en/jp/JVN67792023/397327/index.html | x_refsource_MISC |
| http://jvn.jp/en/jp/JVN67792023/995312/index.html | x_refsource_MISC |
Date Public
2014-12-02 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T12:40:19.271Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVNDB-2014-000137",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000137.html"
},
{
"name": "JVN#67792023",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN67792023/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN67792023/397327/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN67792023/995312/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2014-12-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets 102SH allow local users to execute arbitrary code or read kernel memory via unknown vectors related to userland data and \"improper data validation.\""
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2014-12-05T16:57:00.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVNDB-2014-000137",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000137.html"
},
{
"name": "JVN#67792023",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN67792023/index.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "http://jvn.jp/en/jp/JVN67792023/397327/index.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "http://jvn.jp/en/jp/JVN67792023/995312/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2014-7252",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets 102SH allow local users to execute arbitrary code or read kernel memory via unknown vectors related to userland data and \"improper data validation.\""
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVNDB-2014-000137",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000137.html"
},
{
"name": "JVN#67792023",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN67792023/index.html"
},
{
"name": "http://jvn.jp/en/jp/JVN67792023/397327/index.html",
"refsource": "MISC",
"url": "http://jvn.jp/en/jp/JVN67792023/397327/index.html"
},
{
"name": "http://jvn.jp/en/jp/JVN67792023/995312/index.html",
"refsource": "MISC",
"url": "http://jvn.jp/en/jp/JVN67792023/995312/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2014-7252",
"datePublished": "2014-12-05T17:00:00.000Z",
"dateReserved": "2014-09-30T00:00:00.000Z",
"dateUpdated": "2024-08-06T12:40:19.271Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2013-3655 (GCVE-0-2013-3655)
Vulnerability from nvd – Published: 2013-07-12 16:00 – Updated: 2024-09-17 02:46
VLAI
EPSS
VEX
Summary
The Sharp AQUOS PhotoPlayer HN-PP150 with firmware before 1.04.00.04 allows remote attackers to cause a denial of service (networking outage) via crafted packet data.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://jvndb.jvn.jp/jvndb/JVNDB-2013-000068 | third-party-advisoryx_refsource_JVNDB |
| http://jvn.jp/en/jp/JVN68773685/index.html | third-party-advisoryx_refsource_JVN |
| http://www.sharp.co.jp/support/photoplayer/fw_upd… | x_refsource_CONFIRM |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T16:14:56.572Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVNDB-2013-000068",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000068"
},
{
"name": "JVN#68773685",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN68773685/index.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Sharp AQUOS PhotoPlayer HN-PP150 with firmware before 1.04.00.04 allows remote attackers to cause a denial of service (networking outage) via crafted packet data."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2013-07-12T16:00:00.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVNDB-2013-000068",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000068"
},
{
"name": "JVN#68773685",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN68773685/index.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2013-3655",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The Sharp AQUOS PhotoPlayer HN-PP150 with firmware before 1.04.00.04 allows remote attackers to cause a denial of service (networking outage) via crafted packet data."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVNDB-2013-000068",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000068"
},
{
"name": "JVN#68773685",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN68773685/index.html"
},
{
"name": "http://www.sharp.co.jp/support/photoplayer/fw_update.html",
"refsource": "CONFIRM",
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2013-3655",
"datePublished": "2013-07-12T16:00:00.000Z",
"dateReserved": "2013-05-22T00:00:00.000Z",
"dateUpdated": "2024-09-17T02:46:37.190Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2002-1974 (GCVE-0-2002-1974)
Vulnerability from nvd – Published: 2005-06-28 04:00 – Updated: 2024-09-17 03:02
VLAI
EPSS
VEX
Summary
The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
5 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/5200 | vdb-entryx_refsource_BID |
| http://www.securityfocus.com/archive/1/281549 | mailing-listx_refsource_BUGTRAQ |
| http://online.securityfocus.com/archive/1/281437 | mailing-listx_refsource_BUGTRAQ |
| http://www.iss.net/security_center/static/9534.php | vdb-entryx_refsource_XF |
| http://www.securityfocus.com/archive/1/281652 | mailing-listx_refsource_BUGTRAQ |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-08T03:43:33.653Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "5200",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/5200"
},
{
"name": "20020710 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://www.securityfocus.com/archive/1/281549"
},
{
"name": "20020710 Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://online.securityfocus.com/archive/1/281437"
},
{
"name": "zaurus-insecure-ftp-permissions(9534)",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "http://www.iss.net/security_center/static/9534.php"
},
{
"name": "20020711 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://www.securityfocus.com/archive/1/281652"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2005-06-28T04:00:00.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "5200",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/5200"
},
{
"name": "20020710 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://www.securityfocus.com/archive/1/281549"
},
{
"name": "20020710 Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://online.securityfocus.com/archive/1/281437"
},
{
"name": "zaurus-insecure-ftp-permissions(9534)",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "http://www.iss.net/security_center/static/9534.php"
},
{
"name": "20020711 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://www.securityfocus.com/archive/1/281652"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2002-1974",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "5200",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/5200"
},
{
"name": "20020710 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"refsource": "BUGTRAQ",
"url": "http://www.securityfocus.com/archive/1/281549"
},
{
"name": "20020710 Multiple Security Vulnerabilities in Sharp Zaurus",
"refsource": "BUGTRAQ",
"url": "http://online.securityfocus.com/archive/1/281437"
},
{
"name": "zaurus-insecure-ftp-permissions(9534)",
"refsource": "XF",
"url": "http://www.iss.net/security_center/static/9534.php"
},
{
"name": "20020711 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"refsource": "BUGTRAQ",
"url": "http://www.securityfocus.com/archive/1/281652"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2002-1974",
"datePublished": "2005-06-28T04:00:00.000Z",
"dateReserved": "2005-06-28T04:00:00.000Z",
"dateUpdated": "2024-09-17T03:02:04.572Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-36254 (GCVE-0-2024-36254)
Vulnerability from cvelistv5 – Published: 2024-11-26 07:38 – Updated: 2024-11-26 14:48
VLAI
EPSS
VEX
Summary
Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition.
Severity
7.5 (High)
SSVC
Exploitation: none
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-26 14:24 UTC
CWE
- CWE-125 - Out-of-bounds read
Assigner
References
Impacted products
51 products
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | Multiple MFPs (multifunction printers) |
Affected:
See the information provided by Sharp Corporation listed under [References]
|
|
| Toshiba Tec Corporation | Multiple MFPs (multifunction printers) |
Affected:
See the information provided by Toshiba Tec Corporation listed under [References]
|
|
| sharp | bp-90c70 |
Affected:
0 , ≤ 200
(custom)
cpe:2.3:h:sharp:bp-90c70:-:*:*:*:*:*:*:* |
|
| sharp | bp-90c80 |
Affected:
0 , ≤ 200
(custom)
cpe:2.3:h:sharp:bp-90c80:-:*:*:*:*:*:*:* |
|
| sharp | bp-70c65 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-70c65:-:*:*:*:*:*:*:* |
|
| sharp | bp-70c55 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-70c55:-:*:*:*:*:*:*:* |
|
| sharp | bp-70c45 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-70c45:-:*:*:*:*:*:*:* |
|
| sharp | bp-70c36 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-70c36:-:*:*:*:*:*:*:* |
|
| sharp | bp-70c31 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-70c31:-:*:*:*:*:*:*:* |
|
| sharp | bp-60c45 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-60c45:-:*:*:*:*:*:*:* |
|
| sharp | bp-60c36 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-60c36:-:*:*:*:*:*:*:* |
|
| sharp | bp-60c31 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-60c31:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c65 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c65:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c55 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c55:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c45 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c45:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c36 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c36:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c31 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c31:-:*:*:*:*:*:*:* |
|
| sharp | bp-50c26 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-50c26:-:*:*:*:*:*:*:* |
|
| sharp | bp-55c26 |
Affected:
0 , ≤ 310
(custom)
cpe:2.3:h:sharp:bp-55c26:-:*:*:*:*:*:*:* |
|
| sharp | mx-8081 |
Affected:
0 , ≤ 150
(custom)
cpe:2.3:h:sharp:mx-8081:-:*:*:*:*:*:*:* |
|
| sharp | mx-7081 |
Affected:
0 , ≤ 150
(custom)
cpe:2.3:h:sharp:mx-7081:-:*:*:*:*:*:*:* |
|
| sharp | mx-6071 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-6071:-:*:*:*:*:*:*:* |
|
| sharp | mx-5071 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-5071:-:*:*:*:*:*:*:* |
|
| sharp | mx-4071 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-4071:-:*:*:*:*:*:*:* |
|
| sharp | mx-3571 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3571:-:*:*:*:*:*:*:* |
|
| sharp | mx-3071 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3071:-:*:*:*:*:*:*:* |
|
| sharp | mx-4061 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-4061:-:*:*:*:*:*:*:* |
|
| sharp | mx-3561 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3561:-:*:*:*:*:*:*:* |
|
| sharp | mx-3061 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3061:-:*:*:*:*:*:*:* |
|
| sharp | mx-6051 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-6051:-:*:*:*:*:*:*:* |
|
| sharp | mx-5051 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-5051:-:*:*:*:*:*:*:* |
|
| sharp | mx-4051 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-4051:-:*:*:*:*:*:*:* |
|
| sharp | mx-3551 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3551:-:*:*:*:*:*:*:* |
|
| sharp | mx-3051 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3051:-:*:*:*:*:*:*:* |
|
| sharp | mx-2651 |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-2651:-:*:*:*:*:*:*:* |
|
| sharp | mx-6071s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-6071s:-:*:*:*:*:*:*:* |
|
| sharp | mx-5071s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-5071s:-:*:*:*:*:*:*:* |
|
| sharp | mx-4071s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-4071s:-:*:*:*:*:*:*:* |
|
| sharp | mx-3571s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3571s:-:*:*:*:*:*:*:* |
|
| sharp | mx-3071s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3071s:-:*:*:*:*:*:*:* |
|
| sharp | mx-4061s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-4061s:-:*:*:*:*:*:*:* |
|
| sharp | mx-3561s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3561s:-:*:*:*:*:*:*:* |
|
| sharp | mx-3061s |
Affected:
0 , ≤ 612
(custom)
cpe:2.3:h:sharp:mx-3061s:-:*:*:*:*:*:*:* |
|
| sharp | bp-30c25 |
Affected:
0 , ≤ 123
(custom)
cpe:2.3:h:sharp:bp-30c25:-:*:*:*:*:*:*:* |
|
| sharp | bp-30c25y |
Affected:
0 , ≤ 123
(custom)
cpe:2.3:h:sharp:bp-30c25y:-:*:*:*:*:*:*:* |
|
| sharp | bp-30c25z |
Affected:
0 , ≤ 123
(custom)
cpe:2.3:h:sharp:bp-30c25z:-:*:*:*:*:*:*:* |
|
| sharp | bp-30c25t |
Affected:
0 , ≤ 123
(custom)
cpe:2.3:h:sharp:bp-30c25t:-:*:*:*:*:*:*:* |
|
| sharp | mx-7580n |
Affected:
0 , ≤ 502
(custom)
cpe:2.3:h:sharp:mx-7580n:-:*:*:*:*:*:*:* |
|
| sharp | mx-6580n |
Affected:
0 , ≤ 502
(custom)
cpe:2.3:h:sharp:mx-6580n:-:*:*:*:*:*:*:* |
|
| sharp | mx-8090n |
Affected:
0 , ≤ 404
(custom)
cpe:2.3:h:sharp:mx-8090n:-:*:*:*:*:*:*:* |
|
| sharp | mx-7090n |
Affected:
0 , ≤ 404
(custom)
cpe:2.3:h:sharp:mx-7090n:-:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:h:sharp:bp-90c70:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-90c70",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "200",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-90c80:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-90c80",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "200",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-70c65:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-70c65",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-70c55:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-70c55",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-70c45:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-70c45",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-70c36:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-70c36",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-70c31:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-70c31",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-60c45:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-60c45",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-60c36:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-60c36",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-60c31:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-60c31",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c65:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c65",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c55:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c55",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c45:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c45",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c36:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c36",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c31:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c31",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-50c26:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-50c26",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-55c26:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-55c26",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "310",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-8081:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-8081",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "150",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-7081:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-7081",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "150",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-6071:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-6071",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-5071:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-5071",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-4071:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-4071",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3571:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3571",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3071:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3071",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-4061:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-4061",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3561:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3561",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3061:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3061",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-6051:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-6051",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-5051:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-5051",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-4051:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-4051",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3551:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3551",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3051:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3051",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-2651:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-2651",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-6071s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-6071s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-5071s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-5071s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-4071s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-4071s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3571s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3571s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3071s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3071s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-4061s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-4061s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3561s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3561s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-3061s:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-3061s",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "612",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-30c25:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-30c25",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "123",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-30c25y:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-30c25y",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "123",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-30c25z:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-30c25z",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "123",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-30c25t:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-30c25t",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "123",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-7580n:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-7580n",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "502",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-6580n:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-6580n",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "502",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-8090n:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-8090n",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "404",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-7090n:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-7090n",
"vendor": "sharp",
"versions": [
{
"lessThanOrEqual": "404",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-36254",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-26T14:24:25.876189Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-26T14:48:35.480Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"product": "Multiple MFPs (multifunction printers)",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "See the information provided by Sharp Corporation listed under [References]"
}
]
},
{
"product": "Multiple MFPs (multifunction printers)",
"vendor": "Toshiba Tec Corporation",
"versions": [
{
"status": "affected",
"version": "See the information provided by Toshiba Tec Corporation listed under [References]"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Out-of-bounds read vulnerability exists in Sharp Corporation and Toshiba Tec Corporation multiple MFPs (multifunction printers), which may lead to a denial-of-service (DoS) condition."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-125",
"description": "Out-of-bounds read",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-26T07:38:30.408Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://global.sharp/products/copier/info/info_security_2024-05.html"
},
{
"url": "https://jp.sharp/business/print/information/info_security_2024-05.html"
},
{
"url": "https://www.toshibatec.com/information/20240531_02.html"
},
{
"url": "https://www.toshibatec.co.jp/information/20240531_02.html"
},
{
"url": "https://jvn.jp/en/vu/JVNVU93051062/"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2024-36254",
"datePublished": "2024-11-26T07:38:30.408Z",
"dateReserved": "2024-05-22T09:00:17.089Z",
"dateUpdated": "2024-11-26T14:48:35.480Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2024-36251 (GCVE-0-2024-36251)
Vulnerability from cvelistv5 – Published: 2024-11-26 07:38 – Updated: 2025-11-04 17:21
VLAI
EPSS
VEX
Summary
The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed properly and device-crash happens. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
Severity
7.5 (High)
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-11-26 16:19 UTC
CWE
- CWE-125 - Out-of-bounds read
Assigner
References
7 references
Impacted products
24 products
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | Multiple MFPs (multifunction printers) |
Affected:
See the information provided by Sharp Corporation listed under [References]
|
|
| Toshiba Tec Corporation | Multiple MFPs (multifunction printers) |
Affected:
See the information provided by Toshiba Tec Corporation listed under [References]
|
|
| sharp | mx-m905 |
Affected:
611
cpe:2.3:h:sharp:mx-m905:-:*:*:*:*:*:*:* |
|
| sharp | mx-m6070 |
Affected:
502
cpe:2.3:h:sharp:mx-m6070:-:*:*:*:*:*:*:* |
|
| sharp | mx-m5070 |
Affected:
502
cpe:2.3:h:sharp:mx-m5070:-:*:*:*:*:*:*:* |
|
| sharp | mx-m4070 |
Affected:
502
cpe:2.3:h:sharp:mx-m4070:-:*:*:*:*:*:*:* |
|
| sharp | mx-m3570 |
Affected:
502
cpe:2.3:h:sharp:mx-m3570:-:*:*:*:*:*:*:* |
|
| sharp | mx-m3070 |
Affected:
502
cpe:2.3:h:sharp:mx-m3070:-:*:*:*:*:*:*:* |
|
| sharp | mx-m6050 |
Affected:
502
cpe:2.3:h:sharp:mx-m6050:-:*:*:*:*:*:*:* |
|
| sharp | mx-m5050 |
Affected:
502
cpe:2.3:h:sharp:mx-m5050:-:*:*:*:*:*:*:* |
|
| sharp | mx-m4050 |
Affected:
502
cpe:2.3:h:sharp:mx-m4050:-:*:*:*:*:*:*:* |
|
| sharp | mx-m3550 |
Affected:
502
cpe:2.3:h:sharp:mx-m3550:-:*:*:*:*:*:*:* |
|
| sharp | mx-m3050 |
Affected:
502
cpe:2.3:h:sharp:mx-m3050:-:*:*:*:*:*:*:* |
|
| sharp | mx-m2630 |
Affected:
502
cpe:2.3:h:sharp:mx-m2630:-:*:*:*:*:*:*:* |
|
| sharp | bp-b550wd |
Affected:
250
cpe:2.3:h:sharp:bp-b550wd:-:*:*:*:*:*:*:* |
|
| sharp | bp-b540wr |
Affected:
250
cpe:2.3:h:sharp:bp-b540wr:-:*:*:*:*:*:*:* |
|
| sharp | bp-b547wd |
Affected:
250
cpe:2.3:h:sharp:bp-b547wd:-:*:*:*:*:*:*:* |
|
| sharp | bp-b537wr |
Affected:
250
cpe:2.3:h:sharp:bp-b537wr:-:*:*:*:*:*:*:* |
|
| sharp | mx-b455w |
Affected:
404
cpe:2.3:h:sharp:mx-b455w:-:*:*:*:*:*:*:* |
|
| sharp | mx-b355w |
Affected:
404
cpe:2.3:h:sharp:mx-b355w:-:*:*:*:*:*:*:* |
|
| sharp | mx-b455wz |
Affected:
404
cpe:2.3:h:sharp:mx-b455wz:-:*:*:*:*:*:*:* |
|
| sharp | mx-b355wz |
Affected:
404
cpe:2.3:h:sharp:mx-b355wz:-:*:*:*:*:*:*:* |
|
| sharp | mx-b455wt |
Affected:
404
cpe:2.3:h:sharp:mx-b455wt:-:*:*:*:*:*:*:* |
|
| sharp | mx-b355wt |
Affected:
404
cpe:2.3:h:sharp:mx-b355wt:-:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:h:sharp:mx-m905:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m905",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "611"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m6070:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m6070",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m5070:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m5070",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m4070:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m4070",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m3570:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m3570",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m3070:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m3070",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m6050:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m6050",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m5050:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m5050",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m4050:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m4050",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m3550:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m3550",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m3050:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m3050",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m2630:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m2630",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-m6070:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-m6070",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "502"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-b550wd:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-b550wd",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "250"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-b540wr:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-b540wr",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "250"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-b547wd:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-b547wd",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "250"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:bp-b537wr:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bp-b537wr",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "250"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b455w:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b455w",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b355w:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b355w",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b455wz:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b455wz",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b355wz:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b355wz",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b455wt:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b455wt",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
},
{
"cpes": [
"cpe:2.3:h:sharp:mx-b355wt:-:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "mx-b355wt",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "404"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-36251",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-11-26T16:19:13.648769Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-11-26T16:28:15.625Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2025-11-04T17:21:07.405Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://seclists.org/fulldisclosure/2024/Jul/0"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "Multiple MFPs (multifunction printers)",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "See the information provided by Sharp Corporation listed under [References]"
}
]
},
{
"product": "Multiple MFPs (multifunction printers)",
"vendor": "Toshiba Tec Corporation",
"versions": [
{
"status": "affected",
"version": "See the information provided by Toshiba Tec Corporation listed under [References]"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The web interface of the affected devices process some crafted HTTP requests improperly, leading to a device crash. More precisely, a crafted parameter to billcodedef_sub_sel.html is not processed properly and device-crash happens. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-125",
"description": "Out-of-bounds read",
"lang": "en-US",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-11-26T07:38:24.464Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"url": "https://global.sharp/products/copier/info/info_security_2024-05.html"
},
{
"url": "https://jp.sharp/business/print/information/info_security_2024-05.html"
},
{
"url": "https://www.toshibatec.com/information/20240531_02.html"
},
{
"url": "https://www.toshibatec.co.jp/information/20240531_02.html"
},
{
"url": "https://jvn.jp/en/vu/JVNVU93051062/"
},
{
"url": "https://pierrekim.github.io/blog/2024-06-27-sharp-mfp-17-vulnerabilities.html"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2024-36251",
"datePublished": "2024-11-26T07:38:24.464Z",
"dateReserved": "2024-05-22T09:00:10.181Z",
"dateUpdated": "2025-11-04T17:21:07.405Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2023-38290 (GCVE-0-2023-38290)
Vulnerability from cvelistv5 – Published: 2024-04-22 00:00 – Updated: 2024-08-02 17:39
VLAI
EPSS
VEX
Summary
Certain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with a package name of com.evenwell.fqc (versionCode='9020801', versionName='9.0208.01' ; versionCode='9020913', versionName='9.0209.13' ; versionCode='9021203', versionName='9.0212.03') that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to inadequate access control. No permissions or special privileges are necessary to exploit the vulnerability in the com.evenwell.fqc app. No user interaction is required beyond installing and running a third-party app. The vulnerability allows local apps to access sensitive functionality that is generally restricted to pre-installed apps, such as programmatically performing the following actions: granting arbitrary permissions (which can be used to obtain sensitive user data), installing arbitrary apps, video recording the screen, wiping the device (removing the user's apps and data), injecting arbitrary input events, calling emergency phone numbers, disabling apps, accessing notifications, and much more. The software build fingerprints for each confirmed vulnerable device are as follows: BLU View 2 (BLU/B131DL/B130DL:11/RP1A.200720.011/1672046950:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1663816427:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1656476696:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1647856638:user/release-keys) and Sharp Rouvo V (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_460:user/release-keys and SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys). This malicious app starts an exported activity named com.evenwell.fqc/.activity.ClickTest, crashes the com.evenwell.fqc app by sending an empty Intent (i.e., having not extras) to the com.evenwell.fqc/.FQCBroadcastReceiver receiver component, and then it sends command arbitrary shell commands to the com.evenwell.fqc/.FQCService service component which executes them with "system" privileges.
Severity
7.8 (High)
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2024-05-01 18:49 UTC
CWE
- n/a
- CWE-1263 - Improper Physical Access Control
Assigner
References
1 reference
Impacted products
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:bluview:bluview:2:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "bluview",
"vendor": "bluview",
"versions": [
{
"status": "affected",
"version": "2"
}
]
},
{
"cpes": [
"cpe:2.3:a:sharp:rouvo_v:android_10:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "rouvo_v",
"vendor": "sharp",
"versions": [
{
"status": "affected",
"version": "Android 10"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2023-38290",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-05-01T18:49:30.272312Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1263",
"description": "CWE-1263 Improper Physical Access Control",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-06-04T17:28:22.588Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"providerMetadata": {
"dateUpdated": "2024-08-02T17:39:12.068Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"tags": [
"x_transferred"
],
"url": "https://media.defcon.org/DEF%20CON%2031/DEF%20CON%2031%20presentations/Ryan%20Johnson%20Mohamed%20Elsabagh%20Angelos%20Stavrou%20-%20Still%20Vulnerable%20Out%20of%20the%20Box%20Revisiting%20the%20Security%20of%20Prepaid%20Android%20Carrier%20Devices.pdf"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Certain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with a package name of com.evenwell.fqc (versionCode=\u00279020801\u0027, versionName=\u00279.0208.01\u0027 ; versionCode=\u00279020913\u0027, versionName=\u00279.0209.13\u0027 ; versionCode=\u00279021203\u0027, versionName=\u00279.0212.03\u0027) that allows local third-party apps to execute arbitrary shell commands in its context (system user) due to inadequate access control. No permissions or special privileges are necessary to exploit the vulnerability in the com.evenwell.fqc app. No user interaction is required beyond installing and running a third-party app. The vulnerability allows local apps to access sensitive functionality that is generally restricted to pre-installed apps, such as programmatically performing the following actions: granting arbitrary permissions (which can be used to obtain sensitive user data), installing arbitrary apps, video recording the screen, wiping the device (removing the user\u0027s apps and data), injecting arbitrary input events, calling emergency phone numbers, disabling apps, accessing notifications, and much more. The software build fingerprints for each confirmed vulnerable device are as follows: BLU View 2 (BLU/B131DL/B130DL:11/RP1A.200720.011/1672046950:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1663816427:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1656476696:user/release-keys, BLU/B131DL/B130DL:11/RP1A.200720.011/1647856638:user/release-keys) and Sharp Rouvo V (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_460:user/release-keys and SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys). This malicious app starts an exported activity named com.evenwell.fqc/.activity.ClickTest, crashes the com.evenwell.fqc app by sending an empty Intent (i.e., having not extras) to the com.evenwell.fqc/.FQCBroadcastReceiver receiver component, and then it sends command arbitrary shell commands to the com.evenwell.fqc/.FQCService service component which executes them with \"system\" privileges."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-04-22T14:55:40.228Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://media.defcon.org/DEF%20CON%2031/DEF%20CON%2031%20presentations/Ryan%20Johnson%20Mohamed%20Elsabagh%20Angelos%20Stavrou%20-%20Still%20Vulnerable%20Out%20of%20the%20Box%20Revisiting%20the%20Security%20of%20Prepaid%20Android%20Carrier%20Devices.pdf"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2023-38290",
"datePublished": "2024-04-22T00:00:00.000Z",
"dateReserved": "2023-07-14T00:00:00.000Z",
"dateUpdated": "2024-08-02T17:39:12.068Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2189 (GCVE-0-2017-2189)
Vulnerability from cvelistv5 – Published: 2017-06-09 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in RW-4040 driver installer for Windows 7 version 2.27 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/99290 | vdb-entryx_refsource_BID |
| http://jvn.jp/en/jp/JVN51274854/index.html | third-party-advisoryx_refsource_JVN |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | RW-4040 driver installer for Windows 7 |
Affected:
version 2.27
|
Date Public
2017-06-01 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:04.163Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "RW-4040 driver installer for Windows 7",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 2.27"
}
]
}
],
"datePublic": "2017-06-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in RW-4040 driver installer for Windows 7 version 2.27 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-06-28T09:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2189",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "RW-4040 driver installer for Windows 7",
"version": {
"version_data": [
{
"version_value": "version 2.27"
}
]
}
}
]
},
"vendor_name": "Sharp Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in RW-4040 driver installer for Windows 7 version 2.27 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "99290",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2189",
"datePublished": "2017-06-09T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:04.163Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2192 (GCVE-0-2017-2192)
Vulnerability from cvelistv5 – Published: 2017-06-09 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in RW-5100 tool to verify execution environment for Windows 7 version 1.1.0.0 and RW-5100 tool to verify execution environment for Windows 8.1 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/99290 | vdb-entryx_refsource_BID |
| http://jvn.jp/en/jp/JVN51274854/index.html | third-party-advisoryx_refsource_JVN |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | RW-5100 tool to verify execution environment for Windows 7 |
Affected:
version 1.1.0.0
|
|
| Sharp Corporation | RW-5100 tool to verify execution environment for Windows 8.1 |
Affected:
version 1.2.0.0
|
Date Public
2017-06-01 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:03.652Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "RW-5100 tool to verify execution environment for Windows 7",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 1.1.0.0"
}
]
},
{
"product": "RW-5100 tool to verify execution environment for Windows 8.1",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 1.2.0.0"
}
]
}
],
"datePublic": "2017-06-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in RW-5100 tool to verify execution environment for Windows 7 version 1.1.0.0 and RW-5100 tool to verify execution environment for Windows 8.1 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-06-28T09:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2192",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "RW-5100 tool to verify execution environment for Windows 7",
"version": {
"version_data": [
{
"version_value": "version 1.1.0.0"
}
]
}
},
{
"product_name": "RW-5100 tool to verify execution environment for Windows 8.1",
"version": {
"version_data": [
{
"version_value": "version 1.2.0.0"
}
]
}
}
]
},
"vendor_name": "Sharp Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in RW-5100 tool to verify execution environment for Windows 7 version 1.1.0.0 and RW-5100 tool to verify execution environment for Windows 8.1 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "99290",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2192",
"datePublished": "2017-06-09T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:03.652Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2191 (GCVE-0-2017-2191)
Vulnerability from cvelistv5 – Published: 2017-06-09 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/99290 | vdb-entryx_refsource_BID |
| http://jvn.jp/en/jp/JVN51274854/index.html | third-party-advisoryx_refsource_JVN |
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | RW-5100 driver installer for Windows 7 |
Affected:
version 1.0.0.9
|
|
| Sharp Corporation | RW-5100 driver installer for Windows 8.1 |
Affected:
version 1.0.1.0
|
Date Public
2017-06-01 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:03.670Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "RW-5100 driver installer for Windows 7",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 1.0.0.9"
}
]
},
{
"product": "RW-5100 driver installer for Windows 8.1",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 1.0.1.0"
}
]
}
],
"datePublic": "2017-06-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-06-28T09:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2191",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "RW-5100 driver installer for Windows 7",
"version": {
"version_data": [
{
"version_value": "version 1.0.0.9"
}
]
}
},
{
"product_name": "RW-5100 driver installer for Windows 8.1",
"version": {
"version_data": [
{
"version_value": "version 1.0.1.0"
}
]
}
}
]
},
"vendor_name": "Sharp Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "99290",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2191",
"datePublished": "2017-06-09T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:03.670Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2017-2190 (GCVE-0-2017-2190)
Vulnerability from cvelistv5 – Published: 2017-06-09 16:00 – Updated: 2024-08-05 13:48
VLAI
EPSS
VEX
Summary
Untrusted search path vulnerability in RW-4040 tool to verify execution environment for Windows 7 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Severity
No CVSS data available.
CWE
- Untrusted search path vulnerability
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/99290 | vdb-entryx_refsource_BID |
| http://jvn.jp/en/jp/JVN51274854/index.html | third-party-advisoryx_refsource_JVN |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Sharp Corporation | RW-4040 tool to verify execution environment for Windows 7 |
Affected:
version 1.2.0.0
|
Date Public
2017-06-01 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T13:48:04.327Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "RW-4040 tool to verify execution environment for Windows 7",
"vendor": "Sharp Corporation",
"versions": [
{
"status": "affected",
"version": "version 1.2.0.0"
}
]
}
],
"datePublic": "2017-06-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Untrusted search path vulnerability in RW-4040 tool to verify execution environment for Windows 7 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "Untrusted search path vulnerability",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2017-06-28T09:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "99290",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2017-2190",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "RW-4040 tool to verify execution environment for Windows 7",
"version": {
"version_data": [
{
"version_value": "version 1.2.0.0"
}
]
}
}
]
},
"vendor_name": "Sharp Corporation"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability in RW-4040 tool to verify execution environment for Windows 7 version 1.2.0.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "Untrusted search path vulnerability"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "99290",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/99290"
},
{
"name": "JVN#51274854",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN51274854/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2017-2190",
"datePublished": "2017-06-09T16:00:00.000Z",
"dateReserved": "2016-12-01T00:00:00.000Z",
"dateUpdated": "2024-08-05T13:48:04.327Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2016-1176 (GCVE-0-2016-1176)
Vulnerability from cvelistv5 – Published: 2016-04-05 14:00 – Updated: 2024-08-05 22:48
VLAI
EPSS
VEX
Summary
Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
2 references
| URL | Tags |
|---|---|
| http://jvndb.jvn.jp/jvndb/JVNDB-2016-000038 | third-party-advisoryx_refsource_JVNDB |
| http://jvn.jp/en/jp/JVN41875357/index.html | third-party-advisoryx_refsource_JVN |
Date Public
2016-04-04 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T22:48:13.259Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVNDB-2016-000038",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000038"
},
{
"name": "JVN#41875357",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN41875357/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2016-04-04T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2016-04-05T14:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVNDB-2016-000038",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000038"
},
{
"name": "JVN#41875357",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN41875357/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2016-1176",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVNDB-2016-000038",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000038"
},
{
"name": "JVN#41875357",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN41875357/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2016-1176",
"datePublished": "2016-04-05T14:00:00.000Z",
"dateReserved": "2015-12-26T00:00:00.000Z",
"dateUpdated": "2024-08-05T22:48:13.259Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2016-1175 (GCVE-0-2016-1175)
Vulnerability from cvelistv5 – Published: 2016-04-05 14:00 – Updated: 2024-08-05 22:48
VLAI
EPSS
VEX
Summary
Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://jvn.jp/en/jp/JVN47164236/index.html | third-party-advisoryx_refsource_JVN |
| http://jvndb.jvn.jp/jvndb/JVNDB-2016-000039 | third-party-advisoryx_refsource_JVNDB |
| http://www.sharp.co.jp/support/photoplayer/fw_upd… | x_refsource_CONFIRM |
Date Public
2016-04-04 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-05T22:48:13.087Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVN#47164236",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN47164236/index.html"
},
{
"name": "JVNDB-2016-000039",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000039"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2016-04-04T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2016-04-05T14:57:01.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVN#47164236",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN47164236/index.html"
},
{
"name": "JVNDB-2016-000039",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000039"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2016-1175",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVN#47164236",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN47164236/index.html"
},
{
"name": "JVNDB-2016-000039",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2016-000039"
},
{
"name": "http://www.sharp.co.jp/support/photoplayer/fw_update.html",
"refsource": "CONFIRM",
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2016-1175",
"datePublished": "2016-04-05T14:00:00.000Z",
"dateReserved": "2015-12-26T00:00:00.000Z",
"dateUpdated": "2024-08-05T22:48:13.087Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2014-7252 (GCVE-0-2014-7252)
Vulnerability from cvelistv5 – Published: 2014-12-05 17:00 – Updated: 2024-08-06 12:40
VLAI
EPSS
VEX
Summary
Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets 102SH allow local users to execute arbitrary code or read kernel memory via unknown vectors related to userland data and "improper data validation."
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
4 references
| URL | Tags |
|---|---|
| http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-0… | third-party-advisoryx_refsource_JVNDB |
| http://jvn.jp/en/jp/JVN67792023/index.html | third-party-advisoryx_refsource_JVN |
| http://jvn.jp/en/jp/JVN67792023/397327/index.html | x_refsource_MISC |
| http://jvn.jp/en/jp/JVN67792023/995312/index.html | x_refsource_MISC |
Date Public
2014-12-02 00:00
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T12:40:19.271Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVNDB-2014-000137",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000137.html"
},
{
"name": "JVN#67792023",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN67792023/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN67792023/397327/index.html"
},
{
"tags": [
"x_refsource_MISC",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN67792023/995312/index.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"datePublic": "2014-12-02T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets 102SH allow local users to execute arbitrary code or read kernel memory via unknown vectors related to userland data and \"improper data validation.\""
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2014-12-05T16:57:00.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVNDB-2014-000137",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000137.html"
},
{
"name": "JVN#67792023",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN67792023/index.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "http://jvn.jp/en/jp/JVN67792023/397327/index.html"
},
{
"tags": [
"x_refsource_MISC"
],
"url": "http://jvn.jp/en/jp/JVN67792023/995312/index.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2014-7252",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets 102SH allow local users to execute arbitrary code or read kernel memory via unknown vectors related to userland data and \"improper data validation.\""
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVNDB-2014-000137",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000137.html"
},
{
"name": "JVN#67792023",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN67792023/index.html"
},
{
"name": "http://jvn.jp/en/jp/JVN67792023/397327/index.html",
"refsource": "MISC",
"url": "http://jvn.jp/en/jp/JVN67792023/397327/index.html"
},
{
"name": "http://jvn.jp/en/jp/JVN67792023/995312/index.html",
"refsource": "MISC",
"url": "http://jvn.jp/en/jp/JVN67792023/995312/index.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2014-7252",
"datePublished": "2014-12-05T17:00:00.000Z",
"dateReserved": "2014-09-30T00:00:00.000Z",
"dateUpdated": "2024-08-06T12:40:19.271Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2013-3655 (GCVE-0-2013-3655)
Vulnerability from cvelistv5 – Published: 2013-07-12 16:00 – Updated: 2024-09-17 02:46
VLAI
EPSS
VEX
Summary
The Sharp AQUOS PhotoPlayer HN-PP150 with firmware before 1.04.00.04 allows remote attackers to cause a denial of service (networking outage) via crafted packet data.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
3 references
| URL | Tags |
|---|---|
| http://jvndb.jvn.jp/jvndb/JVNDB-2013-000068 | third-party-advisoryx_refsource_JVNDB |
| http://jvn.jp/en/jp/JVN68773685/index.html | third-party-advisoryx_refsource_JVN |
| http://www.sharp.co.jp/support/photoplayer/fw_upd… | x_refsource_CONFIRM |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-06T16:14:56.572Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "JVNDB-2013-000068",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB",
"x_transferred"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000068"
},
{
"name": "JVN#68773685",
"tags": [
"third-party-advisory",
"x_refsource_JVN",
"x_transferred"
],
"url": "http://jvn.jp/en/jp/JVN68773685/index.html"
},
{
"tags": [
"x_refsource_CONFIRM",
"x_transferred"
],
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Sharp AQUOS PhotoPlayer HN-PP150 with firmware before 1.04.00.04 allows remote attackers to cause a denial of service (networking outage) via crafted packet data."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2013-07-12T16:00:00.000Z",
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert"
},
"references": [
{
"name": "JVNDB-2013-000068",
"tags": [
"third-party-advisory",
"x_refsource_JVNDB"
],
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000068"
},
{
"name": "JVN#68773685",
"tags": [
"third-party-advisory",
"x_refsource_JVN"
],
"url": "http://jvn.jp/en/jp/JVN68773685/index.html"
},
{
"tags": [
"x_refsource_CONFIRM"
],
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "vultures@jpcert.or.jp",
"ID": "CVE-2013-3655",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The Sharp AQUOS PhotoPlayer HN-PP150 with firmware before 1.04.00.04 allows remote attackers to cause a denial of service (networking outage) via crafted packet data."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "JVNDB-2013-000068",
"refsource": "JVNDB",
"url": "http://jvndb.jvn.jp/jvndb/JVNDB-2013-000068"
},
{
"name": "JVN#68773685",
"refsource": "JVN",
"url": "http://jvn.jp/en/jp/JVN68773685/index.html"
},
{
"name": "http://www.sharp.co.jp/support/photoplayer/fw_update.html",
"refsource": "CONFIRM",
"url": "http://www.sharp.co.jp/support/photoplayer/fw_update.html"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"cveId": "CVE-2013-3655",
"datePublished": "2013-07-12T16:00:00.000Z",
"dateReserved": "2013-05-22T00:00:00.000Z",
"dateUpdated": "2024-09-17T02:46:37.190Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}
CVE-2002-1974 (GCVE-0-2002-1974)
Vulnerability from cvelistv5 – Published: 2005-06-28 04:00 – Updated: 2024-09-17 03:02
VLAI
EPSS
VEX
Summary
The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.
Severity
No CVSS data available.
CWE
- n/a
Assigner
References
5 references
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/5200 | vdb-entryx_refsource_BID |
| http://www.securityfocus.com/archive/1/281549 | mailing-listx_refsource_BUGTRAQ |
| http://online.securityfocus.com/archive/1/281437 | mailing-listx_refsource_BUGTRAQ |
| http://www.iss.net/security_center/static/9534.php | vdb-entryx_refsource_XF |
| http://www.securityfocus.com/archive/1/281652 | mailing-listx_refsource_BUGTRAQ |
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2024-08-08T03:43:33.653Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"name": "5200",
"tags": [
"vdb-entry",
"x_refsource_BID",
"x_transferred"
],
"url": "http://www.securityfocus.com/bid/5200"
},
{
"name": "20020710 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://www.securityfocus.com/archive/1/281549"
},
{
"name": "20020710 Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://online.securityfocus.com/archive/1/281437"
},
{
"name": "zaurus-insecure-ftp-permissions(9534)",
"tags": [
"vdb-entry",
"x_refsource_XF",
"x_transferred"
],
"url": "http://www.iss.net/security_center/static/9534.php"
},
{
"name": "20020711 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ",
"x_transferred"
],
"url": "http://www.securityfocus.com/archive/1/281652"
}
],
"title": "CVE Program Container"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2005-06-28T04:00:00.000Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"name": "5200",
"tags": [
"vdb-entry",
"x_refsource_BID"
],
"url": "http://www.securityfocus.com/bid/5200"
},
{
"name": "20020710 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://www.securityfocus.com/archive/1/281549"
},
{
"name": "20020710 Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://online.securityfocus.com/archive/1/281437"
},
{
"name": "zaurus-insecure-ftp-permissions(9534)",
"tags": [
"vdb-entry",
"x_refsource_XF"
],
"url": "http://www.iss.net/security_center/static/9534.php"
},
{
"name": "20020711 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"tags": [
"mailing-list",
"x_refsource_BUGTRAQ"
],
"url": "http://www.securityfocus.com/archive/1/281652"
}
],
"x_legacyV4Record": {
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2002-1974",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"name": "5200",
"refsource": "BID",
"url": "http://www.securityfocus.com/bid/5200"
},
{
"name": "20020710 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"refsource": "BUGTRAQ",
"url": "http://www.securityfocus.com/archive/1/281549"
},
{
"name": "20020710 Multiple Security Vulnerabilities in Sharp Zaurus",
"refsource": "BUGTRAQ",
"url": "http://online.securityfocus.com/archive/1/281437"
},
{
"name": "zaurus-insecure-ftp-permissions(9534)",
"refsource": "XF",
"url": "http://www.iss.net/security_center/static/9534.php"
},
{
"name": "20020711 Re: Multiple Security Vulnerabilities in Sharp Zaurus",
"refsource": "BUGTRAQ",
"url": "http://www.securityfocus.com/archive/1/281652"
}
]
}
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2002-1974",
"datePublished": "2005-06-28T04:00:00.000Z",
"dateReserved": "2005-06-28T04:00:00.000Z",
"dateUpdated": "2024-09-17T03:02:04.572Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.1"
}