Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-6322 | A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A specially crafted message can lead to stack-based buffer overflow. An attacker can make authenticated requests to trigger this vulnerability. NVD description · AI analysis pending | 8.8 group max | 1% | PoC |
| — | |
| CVE-2020-28437 | This affects all versions of package heroku-env. This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2022-27152 | Roku devices running RokuOS v9.4.0 build 4200 or earlier that uses a Realtek WiFi chip is vulnerable to Arbitrary file modification. Roku devices running RokuOS v9.4.0 build 4200 or earlier that uses a Realtek WiFi chip is vulnerable to Arbitrary file modification. NVD description · AI analysis pending | 5.7 | <1% |
| — | ||
| CVE-2020-7634 | heroku-addonpool through 0.1.15 is vulnerable to Command Injection. heroku-addonpool through 0.1.15 is vulnerable to Command Injection. NVD description · AI analysis pending | 9.8 | 3% | PoC ×2 |
| — | |
| CVE-2018-11314 | The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker. NVD description · AI analysis pending | 9.6 | 2% |
| — |