Vulnerabilities > Nttdocomo

DATE CVE VULNERABILITY TITLE RISK
2021-12-01 CVE-2021-20847 Cross-site Scripting vulnerability in Nttdocomo Wi-Fi Station Sh-52A Firmware
Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, 38JP_1_26G, 38JP_1_26J, 38JP_2_03B, and 38JP_2_03C) allows a remote unauthenticated attacker to inject an arbitrary script via WebUI of the device.
network
nttdocomo CWE-79
4.3
2019-02-13 CVE-2019-5914 NULL Pointer Dereference vulnerability in Nttdocomo V20 PRO L-01J Firmware L01J20C/L01J20D
V20 PRO L-01J software version L01J20c and L01J20d has a NULL pointer exception flaw that can be used by an attacker to cause the device to crash on the same network range via a specially crafted access point.
5.7
2017-11-13 CVE-2017-10871 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Nttdocomo Wi-Fi Station L-02F Firmware
Buffer overflow in NTT DOCOMO Wi-Fi STATION L-02F Software version L02F-MDM9625-V10h-JUN-23-2017-DCM-JP and earlier allows an attacker to execute arbitrary code via unspecified vectors.
network
low complexity
nttdocomo CWE-119
critical
10.0
2017-09-15 CVE-2017-10846 Missing Authorization vulnerability in Nttdocomo Wi-Fi Station L-02F Firmware
Wi-Fi STATION L-02F Software version V10b and earlier allows remote attackers to bypass access restrictions to obtain information on device settings via unspecified vectors.
network
low complexity
nttdocomo CWE-862
5.0
2017-09-15 CVE-2017-10845 Unspecified vulnerability in Nttdocomo Wi-Fi Station L-02F Firmware
Wi-Fi STATION L-02F Software version V10g and earlier allows remote attackers to access the device with administrative privileges and perform unintended operations through a backdoor account.
network
low complexity
nttdocomo
critical
10.0
2017-08-29 CVE-2017-10812 Untrusted Search Path vulnerability in Nttdocomo Photo Collection PC Software
Untrusted search path vulnerability in Photo Collection PC Software Ver.4.0.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
network
nttdocomo CWE-426
critical
9.3
2017-05-22 CVE-2016-4854 Cross-Site Request Forgery (CSRF) vulnerability in Nttdocomo L-04D Firmware V10A/V10B
Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijack the authentication of administrators to perform arbitrary operations via unspecified vectors.
network
nttdocomo CWE-352
6.8
2014-03-19 CVE-2014-1979 Code Injection vulnerability in Nttdocomo Spmode Mail Android
The NTT DOCOMO sp mode mail application 5900 through 6300 for Android 4.0.x and 6000 through 6620 for Android 4.1 through 4.4 allows remote attackers to execute arbitrary Java methods via Deco-mail emoticon POP data in an e-mail message.
6.8
2014-03-19 CVE-2014-1978 Permissions, Privileges, and Access Controls vulnerability in Nttdocomo Spmode Mail Android
The application link interface in the NTT DOCOMO sp mode mail application 6100 through 6300 for Android 4.0.x and 6130 through 6700 for Android 4.1 through 4.4 writes message content to the SD card during e-mail composition, which allows attackers to obtain sensitive information via a crafted application.
4.3
2014-03-19 CVE-2014-1977 Permissions, Privileges, and Access Controls vulnerability in Nttdocomo Spmode Mail Android
The NTT DOCOMO sp mode mail application 6300 and earlier for Android 4.0.x and 6700 and earlier for Android 4.1 through 4.4 uses weak permissions for attachments during processing of incoming e-mail messages, which allows attackers to obtain sensitive information via a crafted application.
4.3