Vulnerabilities > Baofeng > Storm > 2.7.9.10

DATE CVE VULNERABILITY TITLE RISK
2009-05-28 CVE-2009-1807 Unspecified vulnerability in Baofeng Storm
Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009.
network
baofeng
critical
9.3
2009-05-11 CVE-2009-1612 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Baofeng Storm
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009.
network
baofeng CWE-119
critical
9.3