VYPR

Vendor CVEs

Philips

All CVEs

125 total · sorted by risk
  • CVE-2019-13557MedNov 8, 2019
    risk 0.35cvss 5.3epss 0.01

    In Tasy EMR, Tasy WebPortal Versions 3.02.1757 and prior, there is an information exposure vulnerability which may allow a remote attacker to access system and configuration information.

  • CVE-2019-6562MedMay 1, 2019
    risk 0.35cvss 5.4epss 0.01

    In Philips Tasy EMR, Tasy EMR Versions 3.02.1744 and prior, the software incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

  • CVE-2018-14803MedSep 26, 2018
    risk 0.35cvss 5.3epss 0.02

    Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that could allow attackers to obtain extraneous product information, such as OS and software components, via the HTTP response header that is…

  • CVE-2015-2883MedApr 10, 2017
    risk 0.35cvss 5.4epss 0.01

    Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to deviceSettings.php or shareDevice.php.

  • CVE-2018-10599MedJun 5, 2018
    risk 0.34cvss 5.3epss 0.00

    IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have…

  • CVE-2020-16198MedSep 18, 2020
    risk 0.33cvss 5.0epss 0.01

    When an attacker claims to have a given identity, Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not prove or insufficiently proves the claim is correct.

  • CVE-2020-16214MedSep 11, 2020
    risk 0.33cvss 5.0epss 0.01

    In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software saves user-provided information into a comma-separated value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the…

  • CVE-2020-16239MedAug 21, 2020
    risk 0.32cvss 4.9epss 0.01

    When an actor claims to have a given identity, Philips SureSigns VS4, A.07.107 and prior does not prove or insufficiently proves the claim is correct.

  • CVE-2019-10968MedJul 24, 2019
    risk 0.29cvss 4.4epss 0.00

    Philips Holter 2010 Plus, all versions. A vulnerability has been identified that may allow system options that were not purchased to be enabled.

  • CVE-2020-16220MedSep 11, 2020
    risk 0.28cvss 4.3epss 0.00

    In Patient Information Center iX (PICiX) Versions C.02, C.03, PerformanceBridge Focal Point Version A.01, the product receives input that is expected to be well-formed (i.e., to comply with a certain syntax) but it does not validate or incorrectly validates that the input …

  • CVE-2018-19001MedDec 7, 2018
    risk 0.28cvss 4.3epss 0.00

    Philips HealthSuite Health Android App, all versions. The software uses simple encryption that is not strong enough for the level of protection required.

  • CVE-2021-32966LowMay 25, 2022
    risk 0.24cvss 3.7epss 0.00

    Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text transmission of sensitive information when configured to use LDAP via TLS and where the domain controller returns LDAP referrals, which may allow an attacker to…

  • CVE-2021-33024LowApr 1, 2022
    risk 0.24cvss 3.7epss 0.01

    Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or retrieval.

  • CVE-2018-14799LowAug 22, 2018
    risk 0.24cvss 3.7epss 0.01

    In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or format string vulnerabilities.

  • CVE-2020-14525LowSep 18, 2020
    risk 0.23cvss 3.5epss 0.00

    Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users.

  • CVE-2020-16218LowSep 11, 2020
    risk 0.23cvss 3.5epss 0.01

    In Patient Information Center iX (PICiX) Versions B.02, C.02, C.03, the software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is then used as a webpage and served to other users. Successful exploitation could lead…

  • CVE-2020-14477LowJun 26, 2020
    risk 0.23cvss 3.6epss 0.00

    In Philips Ultrasound ClearVue Versions 3.2 and prior, Ultrasound CX Versions 5.0.2 and prior, Ultrasound EPIQ/Affiniti Versions VM5.0 and prior, Ultrasound Sparq Version 3.0.2 and prior and Ultrasound Xperius all versions, an attacker may use an alternate path or channel that…

  • CVE-2020-14506LowSep 18, 2020
    risk 0.22cvss 3.4epss 0.00

    Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

  • CVE-2019-10988LowSep 4, 2019
    risk 0.22cvss 3.4epss 0.00

    In Philips HDI 4000 Ultrasound Systems, all versions running on old, unsupported operating systems such as Windows 2000, the HDI 4000 Ultrasound System is built on an old operating system that is no longer supported. Thus, any unmitigated vulnerability in the old operating…

  • CVE-2021-23173LowJan 10, 2022
    risk 0.17cvss 2.6epss 0.01

    The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.

  • CVE-2021-27456LowMar 23, 2022
    risk 0.16cvss 2.4epss 0.00

    Philips Gemini PET/CT family software stores sensitive information in a removable media device that does not have built-in access control.

  • CVE-2020-16237LowAug 21, 2020
    risk 0.14cvss 2.1epss 0.00

    Philips SureSigns VS4, A.07.107 and prior receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly.

  • CVE-2020-12023LowJun 11, 2020
    risk 0.13cvss 2.0epss 0.01

    Philips IntelliBridge Enterprise (IBE), Versions B.12 and prior, IntelliBridge Enterprise system integration with SureSigns (VS4), EarlyVue (VS30) and IntelliVue Guardian (IGS). Unencrypted user credentials received in the IntelliBridge Enterprise (IBE) are logged within the…

  • CVE-2013-2808Oct 5, 2013
    risk 0.00cvss epss 0.04

    Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vascular Monitoring 5 components, and Xper Information Management servers and workstations for Flex Cardio products before XperConnect 1.5.4.053…

  • CVE-2007-5093Sep 26, 2007
    risk 0.00cvss epss 0.00

    The disconnect method in the Philips USB Webcam (pwc) driver in Linux kernel 2.6.x before 2.6.22.6 "relies on user space to close the device," which allows user-assisted local attackers to cause a denial of service (USB subsystem hang and CPU consumption in khubd) by not closing…

Page 3 of 3