Lucene search

K

Yitechnology Security Vulnerabilities

cve
cve

CVE-2018-3910

An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker can cause a camera to connect to this SSID to trigger this vulnerability....

8CVSS

8AI Score

0.001EPSS

2018-11-01 03:29 PM
31
cve
cve

CVE-2018-3935

An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can allocate unlimited memory, resulting in denial of service. An attacker can send a set of packets to trigger this...

7.5CVSS

7.5AI Score

0.001EPSS

2018-11-02 05:29 PM
35
cve
cve

CVE-2018-3928

An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a settings change, resulting in denial of service. An attacker can send a set of packets to trigger this...

7.5CVSS

7.6AI Score

0.003EPSS

2018-11-01 03:29 PM
35
cve
cve

CVE-2018-3947

An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US 1.8.7.0D. An attacker can sniff network traffic to exploit this...

8.1CVSS

7.5AI Score

0.002EPSS

2018-11-01 03:29 PM
30
cve
cve

CVE-2018-3900

An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. An attacker can make the camera scan a QR code to trigger this vulnerability....

8.8CVSS

8.9AI Score

0.004EPSS

2018-11-01 03:29 PM
29
cve
cve

CVE-2018-3899

An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to...

7.5CVSS

8AI Score

0.003EPSS

2018-11-02 05:29 PM
32
cve
cve

CVE-2018-3934

An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a logic flaw, resulting in an authentication bypass. An attacker can sniff network traffic and send a set of packets to trigger.....

9.8CVSS

9.6AI Score

0.004EPSS

2018-11-02 05:29 PM
27
cve
cve

CVE-2018-3891

An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw, resulting in a firmware downgrade. An attacker can insert an SD card to trigger this...

4.6CVSS

4.7AI Score

0.001EPSS

2018-11-02 05:29 PM
32
cve
cve

CVE-2018-3892

An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted packet can cause a buffer overflow, resulting in code execution. An attacker can intercept and alter network traffic to trigger this...

8.1CVSS

8.2AI Score

0.002EPSS

2018-11-02 05:29 PM
30
cve
cve

CVE-2018-3920

An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7.0D. A specially crafted 7-Zip file can cause a CRC collision, resulting in a firmware update and code execution. An attacker can insert an SDcard to trigger this...

6.8CVSS

6.9AI Score

0.001EPSS

2018-11-02 05:29 PM
32
cve
cve

CVE-2018-3898

An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to...

7.5CVSS

8AI Score

0.002EPSS

2018-11-02 05:29 PM
28
cve
cve

CVE-2018-3890

An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw and command injection, resulting in code execution. An attacker can insert an SD card to trigger this...

6.8CVSS

7AI Score

0.001EPSS

2018-11-02 05:29 PM
35