Aleph Research Vulnerability Reports:
- 12/21/23The firmware of the Kontrol Lux lock can be updated w/o AuthZ/AuthC
- 12/21/23The Kontrol Lux lock can be forced to process arbitrary unencrypted messages
- 12/21/23A Gateway G2 can be impersonated using its MAC address
- 12/21/23The TTLock app does not properly verify that it is connected to a real lock
- 12/21/23TTLock virtual keys can be reused even after invalidation
- 12/21/23Challenge response can be retried indefinitely upon failure
- 12/21/23Protocol downgrade on the TTLock app can expose the unlock key
- 12/21/23Challenge response can be retried indefinitely upon failure
- 03/12/23Unauthorized attacker can connect to the MQTT server controlling all of Electra's Smart AC units and gain full control of them
- 03/12/23Attacker within WiFi range can cause unconfigured units to connect to a malicious update server
- 03/12/23Attacker within IR range can install arbitrary firmware over the air
- 03/12/23A WiFi hotspot with a known password is always availiable on unconfigured units
- 03/12/23Credentials for connecting to the MQTT server hardcoded inside the firmware
- 03/12/23Attacker within WiFi range can install arbitrary firmware over the air on unconfigured units
- 06/03/21XXE in JDOM library - Java
- 03/09/21Authenticated Arbitrary File Write via Web UI (cplogo-install)
- 03/09/21Unauthenticated Command Injection via Web UI
- 03/09/21Authenticated Reflected Cross-Site Scripting (cp_perview)
- 03/09/21Authenticated Arbitrary File Write via Web UI to Specific Backup File
- 03/09/21Authenticated Arbitrary File Write via Web UI (cp-upload)
- 03/09/21Unauthenticated Arbitrary File Read via Race Condition Vulnerability
- 03/09/21Authenticated Arbitrary File Read via Web UI (cplogo-install)
- 03/09/21Authenticated Arbitrary Directory Create via Web UI (cplogo-install)
- 01/21/21Stuck reading fifo file in Apport
- 01/21/21Incorrect parsing of /proc/pid/stat in Apport
- 01/21/21Incorrect parsing of /proc/pid/status in Apport
- 06/07/20rkscli jailbreak
- 06/07/20Authenticated command injection in emfd/libemf
- 06/07/20Infromation leakage from /upnp.jsp
- 06/07/20Stack buffer overflow in webs
- 06/07/20Unauthenticated admin credentials overwrite
- 06/07/20Webserver denial fo service
- 06/07/20XSS in /admin/_wla_cmdstat.jsp
- 02/04/20Insufficient validation of untrusted input in Omnibox
- 12/17/19Ruckus CLI (rkscli) jailbreak
- 12/17/19Admin credentials leakage
- 12/17/19Remote command injection via a crafted HTTP request (cmdSpectraAnalysis)
- 12/17/19Remote command injection via a crafted HTTP request (cmdPacketCapture)
- 12/17/19Stack buffer overflow in zap executable
- 12/17/19Remote command injection via a crafted HTTP request (cmdImportCategory)
- 12/17/19Remote command injection via a crafted HTTP request (cmdImportAvpPort)
- 12/17/19Information disclosure vulnerability
- 12/17/19Remote code execution vulnerability via zap
- 12/17/19SSRF vulnerability in zap
- 12/17/19Ruckus CLI (ruckus_cli2) jailbreak
- 10/22/18Potential DOS vulnerability in WCF services
- 10/22/18Potential DOS vulnerability in applications that use ASP.NET Web API
- 10/22/18Applications that use Newtonsoft.Json might be exposed to DOS vulnerability
- 10/22/18DOS vulnerability in Azure Active Directory Graph API
- 10/22/18DOS Vulnerability in SharePoint 2016 Server
- 10/22/18OData Denial of Service Vulnerability
- 01/22/18Nokia 6/5 EDL triggering through USB
- 01/22/18Qualcomm EDL Firehose Programmers Peek and Poke Primitives
- 01/22/18Google Nexus 6 & 6P EDL triggering through ADB
- 01/22/18OnePlus EDL triggering through ADB or Hardware Key Combination
- 01/09/18Motorola Bootloader Old UTAGs may lead to Kernel Command-line Injection
- 08/30/17Motorola Android Bootloader Unlocking a Re-locked Bootloader from Platform OS
- 08/01/17OnePlus 2 Lack of SBL1 Validation Broken Secure Boot
- 06/13/17Google Nexus 9 Ephemeral Access to Unrestricted FIQ Debugger and SysRq
- 05/25/17Apple iOS/watchOS/tvOS IOKit Buffer Overflow in Device-Tree Parsing
- 05/23/17Linux lp.c Out-of-Bounds Write via Kernel Command-line
- 05/23/17Motorola Android Bootloader Kernel Cmdline Injection Secure Boot Bypass
- 05/11/17OnePlus OTA Lack of TLS Vulnerability
- 05/11/17OnePlus OTA One/X Crossover Vulnerability
- 05/11/17OnePlus OTA OxygenOS/HydrogenOS Crossover Vulnerability
- 05/11/17OnePlus OTA Downgrade Vulnerability
- 05/04/17Google Nexus 9 SensorHub Firmware Downgrade Vulnerability
- 05/03/17Google Nexus 9 Cypress SAR Firmware Injection via I2C
- 04/27/17TBA
- 04/25/17OnePlus 3/3T OxygenOS Unauthorized Flash Dumping via fastboot
- 04/06/17TBA
- 03/28/17macOS IOFireWireAVC Kernel Extension Out of Bounds Vulnerability
- 03/26/17OnePlus 3/3T OxygenOS Charger Boot Mode ADB Access
- 03/19/17OnePlus 3/3T OxygenOS Unauthorized Boot Mode Changing
- 03/08/17Google Nexus 9 Unauthorized Access to FIQ Debugger
- 03/01/17TBA
- 02/08/17OnePlus 3/3T OxygenOS 4F500301 Bootloader Locking Bypass
- 02/08/17OnePlus 3/3T OxygenOS dm-verity Security Bypass
- 02/06/17Google Nexus Synaptics Touchscreen Firmware Injection
- 01/27/17Cordova-Android MiTM Remote Code Execution
- 01/11/17OnePlus 3/3T OxygenOS SELinux Security Bypass
- 01/05/17Google Nexus 6/6P Custom Boot Modes USB Configs Override
- 12/05/16Google Android Synaptics Touchscreen Heap Overflow #2
- 12/05/16Google Android Synaptics Touchscreen Heap Overflow
- 10/04/16Google Nexus 6 f_usbnet Kernel Uninitialized Memory Leak Over USB
- 09/05/16Google Nexus 9 Arbitrary Kernel Write
- 09/05/16Google Nexus 5X Bootloader Unauthorized Memory Dumping via USB
- 06/21/16Xiaomi MIUI Analytics Remote Code Execution
- 11/20/15Apple iOS IOMobileFramebuffer Information Disclosure
- 11/20/15Weak Randomization of BridgeSecret for Apache Cordova Android
- 08/10/15MyScript Android SDK Deserialization Code Execution
- 08/10/15GraceNote GNSDK Android SDK Deserialization Code Execution
- 08/10/15PJSIP PJSUA2 Android SDK Deserialization Code Execution
- 08/10/15esri ArcGis Android SDK Deserialization Code Execution
- 08/10/15MetaIO Android SDK Deserialization Code Execution
- 08/10/15Jumio Android SDK Deserialization Code Execution
- 08/10/15Android OpenSSLX509Certificate Deserialization Code Execution
- 12/03/14VASCO MyDigipass OAuth Unverified Email Social Login Bypass
- 12/03/14Amazon OAuth Unverified Email Social Login Bypass
- 12/03/14LinkedIn OAuth Unverified Email Social Login Bypass
- 07/28/14Apache Cordova for Android Leak via URL Loading
- 07/28/14Apache Cordova for Android Cross-App Scripting
- 07/28/14Apache Cordova for Android Whitelist Bypass for Non-HTTP URLs
- 06/30/14Android KeyStore Stack Buffer Overflow
- 03/25/14Firefox for Android Crash Reporter File Manipulation
- 03/25/14Firefox for Android Automatic File Download to SD Card
- 03/25/14Firefox for Android Profile Directory Name Weak Randomization
- 03/11/14Dropbox Android SDK INTERNAL_WEB_HOST Security Bypass
- 02/04/14Firefox for Android Profile Directory Name Leaks to Android System Log
- 12/10/13Android Fragment Injection
- 08/13/13Weak Randomness in Android's DNS Resolver
- 08/13/13BIND 9 NS Selection SRTT Algorithm Weakness
- 10/18/12Dropbox for iOS & Android Cross-Zone Scripting
- 10/18/12Google Drive iOS App Cross-Zone Scripting
- 07/12/12Microsoft Windows Shell Command Injection
- 07/10/12Microsoft toStaticHTML HTML Sanitizing Bypass
- 05/03/12Android SQLite Journal Information Disclosure
- 01/19/12Microsoft Anti-XSS Library Bypass
- 10/18/11Oracle Java Remote DNS Poisoning via Port Exhausion #2
- 10/18/11Microsoft Windows Unprivileged DNS Cache Flushing
- 10/18/11Microsoft Windows Port Exhaustion Weakness
- 10/18/11Oracle Java Remote DNS Poisoning via Port Exhausion
- 10/11/11Google App Engine Python SDK Code Execution
- 09/20/11Opera Mobile for Android Cache Poisoning XAS
- 09/20/11Dolphin Browser HD Cross-Application Scripting
- 07/31/11Android Browser Cross-Application Scripting
- 07/21/11Microsoft toStaticHTML HTML Sanitizing Information Leak Vulnerability
- 08/02/09Adobe Flash Player and AIR AVM2 intf_count Integer Overflow
- 06/02/09Apple QuickTime Image Description Atom Sign Extension Memory Corruption
- 04/23/09Google Chrome ChromeHTML Protocol Handler Universal XSS
- 10/08/08Adobe Flash Out-of-Bounds Memory Read DoS
- 10/08/08Graphviz Stack Buffer Overflow Code Execution
- 09/09/08Apple QuickTime QTVR Sign-Extension Heap Overflow