Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Logi Options\+ HIGH 7.8
CVE-2024-8258

Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to…

Fix: 1.70.551909+
Fix from $1,950 2024-09-10
Options\+ MEDIUM 5.5
CVE-2024-8011

Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within Options+ runtime and abuse permissions granted by the …

Fix: 1.72+
Fix from $1,600 2024-08-25
Logi Tune CRITICAL 9.8
CVE-2024-2537

Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion.

Mitigation only
Fix from $2,300 2024-03-15
Streamlabs Desktop HIGH 7.3
CVE-2022-36263

StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .e…

No fix yet
Fix from $1,950 2022-08-19
Options HIGH 8.8
CVE-2022-0916

An issue was discovered in Logitech Options. The OAuth 2.0 state parameter was not properly validated. This leaves applications vulnerable to CSRF at…

Fix: 9.60.87+
Fix from $1,950 2022-05-03
Sync HIGH 7.0
CVE-2022-0915

There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Logitech Sync for Windows prior to 2.4.574. Successful exploitation of …

Fix: 2.4.574+
Fix from $1,950 2022-04-12
Z120 Firmware MEDIUM 5.9
CVE-2021-38547

Logitech Z120 and S120 speakers through 2021-08-09 allow remote attackers to recover speech signals from an LED on the device, via a telescope and an…

Fix: after 2021-08-09
Fix from $1,600 2021-08-11
Lan W300n\/pgrb Firmware MEDIUM 6.8
CVE-2021-20638

LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

Mitigation only
Fix from $1,600 2021-02-12
Lan W300n\/pgrb Firmware MEDIUM 6.8
CVE-2021-20639

LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

Mitigation only
Fix from $1,600 2021-02-12
Lan W300n\/pgrb Firmware MEDIUM 6.8
CVE-2021-20640

Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspe…

Mitigation only
Fix from $1,600 2021-02-12
Lan Wh450n\/gr Firmware MEDIUM 6.5
CVE-2021-20635

Improper restriction of excessive authentication attempts in LOGITEC LAN-WH450N/GR allows an attacker in the wireless range of the device to recover …

Mitigation only
Fix from $1,600 2021-02-12
Lan W300n\/pr5b Firmware MEDIUM 6.5
CVE-2021-20636

Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/PR5B allows remote attackers to hijack the authentication of administrators via …

Mitigation only
Fix from $1,600 2021-02-12
Lan W300n\/pr5b Firmware MEDIUM 6.5
CVE-2021-20637

Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) condition …

Mitigation only
Fix from $1,600 2021-02-12
Lan W300n\/rs Firmware MEDIUM 6.5
CVE-2021-20641

Cross-site request forgery (CSRF) vulnerability in LOGITEC LAN-W300N/RS allows remote attackers to hijack the authentication of administrators via a …

Mitigation only
Fix from $1,600 2021-02-12
Lan W300n\/rs Firmware MEDIUM 6.5
CVE-2021-20642

Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by…

Mitigation only
Fix from $1,600 2021-02-12
K400r Firmware MEDIUM 6.5
CVE-2016-10761

Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.

Mitigation only
Fix from $1,600 2019-06-29
Unifying Receiver Firmware MEDIUM 6.5
CVE-2019-13052

Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.

No fix yet
Fix from $1,600 2019-06-29
Unifying Receiver Firmware MEDIUM 6.5
CVE-2019-13053

Logitech Unifying devices allow keystroke injection, bypassing encryption. The attacker must press a "magic" key combination while sniffing cryptogra…

No fix yet
Fix from $1,600 2019-06-29
R500 Firmware MEDIUM 6.5
CVE-2019-13054

The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injecte…

No fix yet
Fix from $1,600 2019-06-29
Unifying Receiver Firmware MEDIUM 6.5
CVE-2019-13055

Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Frequency tra…

No fix yet
Fix from $1,600 2019-06-29
R700 Laser Presentation Remote Firmware HIGH 8.8
CVE-2019-12506

Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone to keystro…

No fix yet
Fix from $1,950 2019-06-07
Harmony Hub Firmware CRITICAL 9.8
CVE-2018-15720

Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.

Fix: 4.15.206+
Fix from $2,300 2018-12-20
Harmony Hub Firmware CRITICAL 9.8
CVE-2018-15721

The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers c…

Fix: 4.15.206+
Fix from $2,300 2018-12-20
Harmony Hub Firmware CRITICAL 9.8
CVE-2018-15723

The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated re…

Fix: 4.15.206+
Fix from $2,300 2018-12-20
Harmony Hub Firmware HIGH 8.1
CVE-2018-15722

The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the mid…

Fix: 4.15.206+
Fix from $1,950 2018-12-20
Game Software HIGH 7.8
CVE-2018-0620

Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan horse DLL i…

Fix: 8.87.116+
Fix from $1,950 2018-07-26
Connection Utility Software HIGH 7.8
CVE-2018-0621

Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via a Trojan…

Fix: 2.30.9+
Fix from $1,950 2018-07-26
Media Server MEDIUM 5.4
CVE-2017-16567

Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remo…

No fix yet
Fix from $1,600 2017-11-10
Media Server MEDIUM 5.4
CVE-2017-16568

Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows at…

No fix yet
Fix from $1,600 2017-11-10
Media Server MEDIUM 6.1
CVE-2017-15687

DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI.

No fix yet
Fix from $1,600 2017-10-23