Mini
by Birddog
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-2504 | Hig | 0.55 | 8.4 | 0.00 | May 22, 2023 | Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials. | ||
| CVE-2023-2505 | Hig | 0.50 | 7.7 | 0.00 | May 22, 2023 | The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files. | ||
| CVE-2023-25758 | Med | 0.27 | 4.2 | 0.00 | Feb 14, 2023 | Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain the seed phase. The man-in-the-middle access can only be obtained after disassembling a device (i.e., here, "man-in-the-middle" does not refer to the attacker's… | ||
| CVE-2006-5019 | 0.03 | — | 0.04 | Sep 27, 2006 | Google Mini 4.4.102.M.36 and earlier allows remote attackers to obtain sensitive information via a direct request for /search with an invalid client parameter, which reveals the path in an error message. | |||
| CVE-2006-6223 | 0.00 | — | 0.03 | Dec 2, 2006 | Cross-site scripting (XSS) vulnerability in Google Search Appliance and Google Mini allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded q parameter. |
- risk 0.55cvss 8.4epss 0.00
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.
- risk 0.50cvss 7.7epss 0.00
The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files.
- risk 0.27cvss 4.2epss 0.00
Onekey Touch devices through 4.0.0 and Onekey Mini devices through 2.10.0 allow man-in-the-middle attackers to obtain the seed phase. The man-in-the-middle access can only be obtained after disassembling a device (i.e., here, "man-in-the-middle" does not refer to the attacker's…
- CVE-2006-5019Sep 27, 2006risk 0.03cvss —epss 0.04
Google Mini 4.4.102.M.36 and earlier allows remote attackers to obtain sensitive information via a direct request for /search with an invalid client parameter, which reveals the path in an error message.
- CVE-2006-6223Dec 2, 2006risk 0.00cvss —epss 0.03
Cross-site scripting (XSS) vulnerability in Google Search Appliance and Google Mini allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded q parameter.