Vulnerabilities > Securifi > Almond 2015 Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-06-18 CVE-2017-8337 Information Exposure vulnerability in Securifi products
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096.
network
securifi CWE-200
6.8
2019-06-18 CVE-2017-8334 Cross-Site Request Forgery (CSRF) vulnerability in Securifi products
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096.
network
securifi CWE-352
6.0
2019-06-18 CVE-2017-8332 Cross-site Scripting vulnerability in Securifi products
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096.
network
low complexity
securifi CWE-79
6.5
2019-06-18 CVE-2017-8331 Command Injection vulnerability in Securifi products
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096.
network
low complexity
securifi CWE-77
6.5
2019-06-18 CVE-2017-8329 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Securifi products
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096.
network
high complexity
securifi CWE-119
4.6
2019-06-18 CVE-2017-8336 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Securifi products
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096.
network
low complexity
securifi CWE-119
6.5
2019-06-18 CVE-2017-8335 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Securifi products
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096.
network
securifi CWE-119
6.0
2015-09-21 CVE-2015-7296 Unspecified vulnerability in Securifi Almond-2015 Firmware and Almond Firmware
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a linear algorithm for selecting the ID value in the header of a DNS query performed on behalf of the device itself, which makes it easier for remote attackers to spoof responses by including this ID value, as demonstrated by a response containing the address of the firmware update server, a different vulnerability than CVE-2015-2914.
network
securifi
4.3
2015-09-21 CVE-2015-2917 Improper Input Validation vulnerability in Securifi Almond-2015 Firmware and Almond Firmware
Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M unintentionally omit the X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site that contains a (1) FRAME, (2) IFRAME, or (3) OBJECT element.
network
securifi CWE-20
4.3
2015-09-21 CVE-2015-2916 Cross-Site Request Forgery (CSRF) vulnerability in Securifi Almond-2015 Firmware and Almond Firmware
Cross-site request forgery (CSRF) vulnerability on Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M allows remote attackers to hijack the authentication of arbitrary users.
network
securifi CWE-352
6.8