Vulnerabilities > Sony
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-11-14 | CVE-2019-15744 | Externally Controlled Reference to a Resource in Another Sphere vulnerability in Sony Xperia XZS Firmware The Sony Xperia Xperia XZs Android device with a build fingerprint of Sony/keyaki_softbank/keyaki_softbank:7.1.1/TONE3-3.0.0-SOFTBANK-170517-0323/1:user/dev-keys contains a pre-installed app with a package name of jp.softbank.mb.tdrl app (versionCode=1413005, versionName=1.3.0) that allows unauthorized wireless settings modification via a confused deputy attack. | 3.3 |
2019-11-14 | CVE-2019-15743 | Externally Controlled Reference to a Resource in Another Sphere vulnerability in Sony Xperia Touch Firmware The Sony Xperia Touch Android device with a build fingerprint of Sony/blanc_windy/blanc_windy:7.0/LOIRE-SMART-BLANC-1.0.0-170530-0834/1:user/dev-keys contains a pre-installed app with a package name of com.sonymobile.android.maintenancetool.testmic app (versionCode=24, versionName=7.0) that allows unauthorized microphone audio recording via a confused deputy attack. | 5.5 |
2019-11-14 | CVE-2019-15416 | Unspecified vulnerability in Sony Xperia XZS Firmware The Sony keyaki_kddi Android device with a build fingerprint of Sony/keyaki_kddi/keyaki_kddi:7.1.1/TONE3-3.0.0-KDDI-170517-0326/1:user/dev-keys contains a pre-installed app with a package name of com.kddi.android.packageinstaller app (versionCode=70008, versionName=08.10.03) that allows other pre-installed apps to perform app installation via an accessible app component. | 7.8 |
2019-07-09 | CVE-2019-11890 | Resource Exhaustion vulnerability in Sony Bravia Firmware Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood attack over a wired or Wi-Fi LAN. | 7.5 |
2019-07-09 | CVE-2019-11889 | Unspecified vulnerability in Sony Bravia Firmware Sony BRAVIA Smart TV devices allow remote attackers to cause a denial of service (device hang) via a crafted web page over HbbTV. | 7.5 |
2019-07-05 | CVE-2019-5982 | Download of Code Without Integrity Check vulnerability in Sony Vaio Update 7.3.0.03150 Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to conduct a man-in-the-middle attack via a malicous wireless LAN access point. | 7.5 |
2019-07-05 | CVE-2019-5981 | Unspecified vulnerability in Sony Vaio Update 7.3.0.03150 Improper authorization vulnerability in VAIO Update 7.3.0.03150 and earlier allows an attackers to execute arbitrary executable file with administrative privilege via unspecified vectors. | 7.8 |
2019-06-19 | CVE-2018-16595 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Sony products The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices has a Buffer Overflow. | 6.5 |
2019-06-19 | CVE-2018-16594 | Path Traversal vulnerability in Sony products The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal. | 8.1 |
2019-06-19 | CVE-2018-16593 | OS Command Injection vulnerability in Sony products The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection. | 8.8 |