Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Sweet B MEDIUM 5.3
CVE-2022-23001

When compressing or decompressing elliptic curve points using the Sweet B library, an incorrect choice of sign bit is used. An attacker with user lev…

Mitigation only
Fix from $1,600 2022-07-29
Sweet B MEDIUM 5.3
CVE-2022-23002

When compressing or decompressing a point on the NIST P-256 elliptic curve with an X coordinate of zero, the resulting output is not properly reduced…

Mitigation only
Fix from $1,600 2022-07-29
Sweet B MEDIUM 5.3
CVE-2022-23003

When computing a shared secret or point multiplication on the NIST P-256 curve that results in an X coordinate of zero, the resulting output is not p…

Mitigation only
Fix from $1,600 2022-07-29
Sweet B MEDIUM 5.3
CVE-2022-23004

When computing a shared secret or point multiplication on the NIST P-256 curve using a public key with an X coordinate of zero, an error is returned …

Mitigation only
Fix from $1,600 2022-07-29
Wd My Book Live Firmware HIGH 7.5
CVE-2021-35941EPSS 13%

Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory re…

No fix yet
Fix from $1,950 2021-06-29
Sandisk X600 Sd9tb8w 128g Firmware HIGH 7.5
CVE-2019-10705

Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be dec…

Mitigation only
Fix from $1,950 2020-03-10
Sandisk X600 Sd9tb8w 128g Firmware MEDIUM 6.3
CVE-2019-10706

Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The…

Mitigation only
Fix from $1,600 2020-03-10
Sandisk X600 Sd9tb8w 128g Firmware MEDIUM 5.5
CVE-2019-11686

Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically …

Mitigation only
Fix from $1,600 2020-03-10
My Book Live Firmware CRITICAL 9.8
CVE-2018-18472EPSS 30%

Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/…

Mitigation only
Fix from $2,300 2019-06-19
Tv Live Hub Firmware CRITICAL 9.8
CVE-2018-1151EPSS 8%

The web server on Western Digital TV Media Player 1.03.07 and TV Live Hub 3.12.13 allow unauthenticated remote attackers to execute arbitrary code or…

No fix yet
Fix from $2,300 2018-06-12
My Cloud Firmware CRITICAL 9.8
CVE-2018-9148

Western Digital WD My Cloud v04.05.00-320 devices embed the session token (aka PHPSESSID) in filenames, which makes it easier for attackers to bypass…

No fix yet
Fix from $2,300 2018-03-30
Wd My Cloud MEDIUM 5.4
CVE-2014-5876

The WD My Cloud (aka com.wdc.wd2go) application 4.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle…

Mitigation only
Fix from $1,600 2014-09-11