Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2024-8258 Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to… Logi Options\+ 1.70.551909+ Fix from $1,9502024-09-10 MEDIUM 5.5 CVE-2024-8011 Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the … Options\+ 1.72+ Fix from $1,6002024-08-25 CRITICAL 9.8 CVE-2024-2537 Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion. Logi Tune Mitigation only Fix from $2,3002024-03-15 HIGH 7.3 CVE-2022-36263 StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .e… Streamlabs Desktop No fix yet Fix from $1,9502022-08-19 HIGH 8.8 CVE-2022-0916 An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF at… Options 9.60.87+ Fix from $1,9502022-05-03 HIGH 7.0 CVE-2022-0915 There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of … Sync 2.4.574+ Fix from $1,9502022-04-12 MEDIUM 5.9 CVE-2021-38547 Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an… Z120 Firmware after 2021-08-09 Fix from $1,6002021-08-11 MEDIUM 6.8 CVE-2021-20638 LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors. Lan W300n\/pgrb Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.8 CVE-2021-20639 LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors. Lan W300n\/pgrb Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.8 CVE-2021-20640 Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspe… Lan W300n\/pgrb Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2021-20635 Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover … Lan Wh450n\/gr Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2021-20636 Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via … Lan W300n\/pr5b Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2021-20637 Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition … Lan W300n\/pr5b Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2021-20641 Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a … Lan W300n\/rs Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2021-20642 Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by… Lan W300n\/rs Firmware Mitigation only Fix from $1,6002021-02-12 MEDIUM 6.5 CVE-2016-10761 Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack. K400r Firmware Mitigation only Fix from $1,6002019-06-29 MEDIUM 6.5 CVE-2019-13052 Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed. Unifying Receiver Firmware No fix yet Fix from $1,6002019-06-29 MEDIUM 6.5 CVE-2019-13053 Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptogra… Unifying Receiver Firmware No fix yet Fix from $1,6002019-06-29 MEDIUM 6.5 CVE-2019-13054 The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injecte… R500 Firmware No fix yet Fix from $1,6002019-06-29 MEDIUM 6.5 CVE-2019-13055 Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency tra… Unifying Receiver Firmware No fix yet Fix from $1,6002019-06-29 HIGH 8.8 CVE-2019-12506 Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystro… R700 Laser Presentation Remote Firmware No fix yet Fix from $1,9502019-06-07 CRITICAL 9.8 CVE-2018-15720 Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API. Harmony Hub Firmware 4.15.206+ Fix from $2,3002018-12-20 CRITICAL 9.8 CVE-2018-15721 The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers c… Harmony Hub Firmware 4.15.206+ Fix from $2,3002018-12-20 CRITICAL 9.8 CVE-2018-15723 The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated re… Harmony Hub Firmware 4.15.206+ Fix from $2,3002018-12-20 HIGH 8.1 CVE-2018-15722 The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the mid… Harmony Hub Firmware 4.15.206+ Fix from $1,9502018-12-20 HIGH 7.8 CVE-2018-0620 Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL i… Game Software 8.87.116+ Fix from $1,9502018-07-26 HIGH 7.8 CVE-2018-0621 Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan… Connection Utility Software 2.30.9+ Fix from $1,9502018-07-26 MEDIUM 5.4 CVE-2017-16567 Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remo… Media Server No fix yet Fix from $1,6002017-11-10 MEDIUM 5.4 CVE-2017-16568 Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows at… Media Server No fix yet Fix from $1,6002017-11-10 MEDIUM 6.1 CVE-2017-15687 DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI. Media Server No fix yet Fix from $1,6002017-10-23