Vulnerabilities > Philips > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-05-01 CVE-2019-6562 Cross-site Scripting vulnerability in Philips Tasy EMR 3.02.1744
In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
network
low complexity
philips CWE-79
5.4
2018-12-07 CVE-2018-19001 Inadequate Encryption Strength vulnerability in Philips Healthsuite Health
Philips HealthSuite Health Android App, all versions.
local
low complexity
philips CWE-326
4.6
2018-09-26 CVE-2018-8856 Use of Hard-coded Credentials vulnerability in Philips E-Alert Firmware
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
network
low complexity
philips CWE-798
5.0
2018-09-26 CVE-2018-8854 Resource Exhaustion vulnerability in Philips E-Alert Firmware
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
network
low complexity
philips CWE-400
5.0
2018-09-26 CVE-2018-8852 Session Fixation vulnerability in Philips E-Alert Firmware
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
network
philips CWE-384
6.8
2018-09-26 CVE-2018-8848 Incorrect Default Permissions vulnerability in Philips E-Alert Firmware
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
network
low complexity
philips CWE-276
5.0
2018-09-26 CVE-2018-8846 Cross-site Scripting vulnerability in Philips E-Alert Firmware
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
network
philips CWE-79
4.3
2018-09-26 CVE-2018-8844 Cross-Site Request Forgery (CSRF) vulnerability in Philips E-Alert Firmware
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
network
philips CWE-352
6.8
2018-09-26 CVE-2018-14803 Information Exposure vulnerability in Philips E-Alert Firmware
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
network
low complexity
philips CWE-200
5.0
2018-08-22 CVE-2018-14799 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Philips products
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user.
local
low complexity
philips CWE-119
4.6