VYPR

Vendor CVEs

Motorola

All CVEs

145 total · sorted by risk
  • CVE-2022-3407MedSep 1, 2023
    risk 0.32cvss 4.9epss 0.00

    I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user…

  • CVE-2023-41822MedMay 3, 2024
    risk 0.31cvss 4.8epss 0.00

    An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands. 

  • CVE-2021-38701MedDec 15, 2021
    risk 0.31cvss 4.8epss 0.00

    Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180.

  • CVE-2024-38280MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.

  • CVE-2024-38279MedJun 13, 2024
    risk 0.30cvss 4.6epss 0.00

    The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.

  • CVE-2022-3917MedDec 14, 2022
    risk 0.30cvss 4.6epss 0.00

    Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.267-38-8 allows attacker with local access to read partition or RAM data.

  • CVE-2017-9495MedJul 31, 2017
    risk 0.30cvss 4.6epss 0.00

    The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to read arbitrary files by pressing "EXIT, Down, Down, 2" on an RF4CE remote to reach the diagnostic display, and then launching a Remote Web…

  • CVE-2023-41828MedMay 3, 2024
    risk 0.29cvss 4.4epss 0.00

    An implicit intent export vulnerability was reported in the Motorola Phone application, that could allow unauthorized access to a non-exported content provider.  

  • CVE-2023-41823MedMay 3, 2024
    risk 0.29cvss 4.4epss 0.00

    An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities. 

  • CVE-2021-3789MedNov 12, 2021
    risk 0.27cvss 4.2epss 0.00

    An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages.

  • CVE-2025-2818LowJul 17, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was reported in version 1.0 of the Bluetooth Transmission Alliance protocol adopted by Motorola Smart Connect Android Application that could allow a nearby attacker within the Bluetooth interaction range to intercept files when transferred to a device not paired…

  • CVE-2023-38301LowApr 22, 2024
    risk 0.22cvss 3.4epss 0.00

    An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers. Various software builds for the BLU View 2, Boost Mobile Celero 5G, Sharp Rouvo V, Motorola Moto G Pure, Motorola Moto G Power, T-Mobile Revvl…

  • CVE-2025-1699LowJun 11, 2025
    risk 0.18cvss 2.8epss 0.00

    An incorrect default permissions vulnerability was reported in the MotoSignature application that could result in unauthorized access.

  • CVE-2025-1698LowJun 11, 2025
    risk 0.18cvss 2.8epss 0.00

    Null pointer exception vulnerabilities were reported in the fingerprint sensor service that could allow a local attacker to cause a denial of service.

  • CVE-2022-4003LowJul 31, 2024
    risk 0.18cvss 2.7epss 0.00

    A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request.

  • CVE-2024-3480LowMay 3, 2024
    risk 0.18cvss 2.8epss 0.00

    An Implicit intent vulnerability was reported in the Motorola framework that could allow an attacker to read telephony-related data.

  • CVE-2024-3479LowMay 3, 2024
    risk 0.18cvss 2.8epss 0.00

    An improper export vulnerability was reported in the Motorola Enterprise MotoDpms Provider (com.motorola.server.enterprise.MotoDpmsProvider) that could allow a local attacker to read local data.

  • CVE-2023-41825LowMay 3, 2024
    risk 0.18cvss 2.8epss 0.00

    A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to access local files. 

  • CVE-2023-41824LowMay 3, 2024
    risk 0.18cvss 2.8epss 0.00

    An implicit intent vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read the calling phone number and calling data.

  • CVE-2023-41817LowMay 3, 2024
    risk 0.18cvss 2.8epss 0.00

    An improper export vulnerability was reported in the Motorola Phone Calls application that could allow a local attacker to read unauthorized information.

  • CVE-2009-1394Jun 26, 2009
    risk 0.06cvss epss 0.33

    Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe.

  • CVE-2010-2307Jun 16, 2010
    risk 0.04cvss epss 0.09

    Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded…

  • CVE-2006-5196Oct 10, 2006
    risk 0.04cvss epss 0.07

    The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.

  • CVE-2004-1550Dec 31, 2004
    risk 0.04cvss epss 0.19

    Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on.

  • CVE-2009-0393Feb 3, 2009
    risk 0.03cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to inject arbitrary web script or HTML via the page parameter.

  • CVE-2009-0392Feb 3, 2009
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter.

  • CVE-2007-4220Aug 29, 2007
    risk 0.03cvss epss 0.04

    Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or delete arbitrary files via a .. (dot dot) in a Send request, probably related to the (1) Send and (2) Exchange services.

  • CVE-2006-1367Mar 23, 2006
    risk 0.03cvss epss 0.03

    The Motorola PEBL U6 08.83.76R, the Motorola V600, and possibly the Motorola E398 and other Motorola P2K-based phones does not require pairing for a connection related to the Headset Audio Gateway service, which allows user-assisted remote attackers to obtain AT level access and…

  • CVE-2007-4221Aug 29, 2007
    risk 0.01cvss epss 0.06

    Multiple buffer overflows in Motorola Timbuktu Pro before 8.6.5 for Windows allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via (1) a long user name and (2) certain malformed requests; and (3) allow remote Timbuktu servers to…

  • CVE-2015-1496Feb 16, 2015
    risk 0.00cvss epss 0.00

    Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerService.exe, which allows local users to gain privileges via unspecified vectors.

  • CVE-2015-1495Feb 16, 2015
    risk 0.00cvss epss 0.03

    Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a crafted string to the Open method in (1) IOPOSScanner.ocx or (2) IOPOSScale.ocx.

  • CVE-2013-5933Sep 25, 2013
    risk 0.00cvss epss 0.00

    Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless allows local users to gain privileges or cause a denial of service (memory corruption) by writing a long string to the…

  • CVE-2013-4777Sep 25, 2013
    risk 0.00cvss epss 0.00

    A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that listens for shell commands, which allows local users to gain privileges by interacting with a LocalSocket object.

  • CVE-2013-3051Apr 13, 2013
    risk 0.00cvss epss 0.00

    The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the association between a certain physical-address argument and a memory region,…

  • CVE-2008-2548Jun 4, 2008
    risk 0.00cvss epss 0.06

    Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malformed JPEG image, which triggers memory corruption.

  • CVE-2008-2002Apr 28, 2008
    risk 0.00cvss epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Modem" value in the BUTTON_INPUT parameter to configdata.html,…

  • CVE-2007-5761Jan 9, 2008
    risk 0.00cvss epss 0.00

    The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which allows local users to gain privileges or cause a denial of service (system crash), as demonstrated by modifying the…

  • CVE-2007-5792Nov 1, 2007
    risk 0.00cvss epss 0.01

    The Vonage Motorola Phone Adapter VT 2142-VD does not encrypt RTP packets, which might allow remote attackers to eavesdrop by sniffing the network and reconstructing the RTP session.

  • CVE-2007-0522Jan 26, 2007
    risk 0.00cvss epss 0.01

    The Motorola MOTORAZR V3 phone allows remote attackers to cause a denial of service (continual modal dialogs and UI unavailability) by repeatedly trying to OBEX push a file over Bluetooth, as demonstrated by ussp-push.

  • CVE-2006-1366Mar 23, 2006
    risk 0.00cvss epss 0.05

    Buffer overflow in the Motorola PEBL U6 08.83.76R, and possibly other Motorola P2K-based phones, allows remote attackers to cause a denial of service (device shutdown), and possibly execute arbitrary code, via a long OBEX setpath to the OBEX File Transfer (aka FTP) service on…

  • CVE-2006-1365Mar 23, 2006
    risk 0.00cvss epss 0.01

    The Motorola PEBL U6, the Motorola V600, and possibly the Motorola E398 and other Motorola phones allow remote attackers to add an entry for their own Bluetooth device to a target device's list of trusted devices (aka Device History), and possibly obtain AT level access to the…

  • CVE-2005-4215Dec 14, 2005
    risk 0.00cvss epss 0.02

    Motorola SB5100E Cable Modem allows remote attackers to cause a denial of service (device crash) via an IP packet with the same source and destination IPs and ports, and with the SYN flag set (aka LAND).

  • CVE-2002-1944Dec 31, 2002
    risk 0.00cvss epss 0.02

    Motorola Surfboard 4200 cable modem allows remote attackers to cause a denial of service (crash) by performing a SYN scan using a tool such as nmap.

  • CVE-1999-0919May 10, 1998
    risk 0.00cvss epss 0.03

    A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.

  • CVE-1999-0816May 10, 1998
    risk 0.00cvss epss 0.03

    The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.

Page 3 of 3