VYPR

Vendor CVEs

Sharp

All CVEs

68 total · sorted by risk
  • CVE-2002-1975MedDec 31, 2002
    risk 0.36cvss 5.5epss 0.00

    Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods.

  • CVE-2024-34162MedNov 26, 2024
    risk 0.35cvss 5.3epss 0.01

    The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users. But configuring LDAP authentication to "SIMPLE", the device communicates with the LDAP server in clear-text. The LDAP password can be retrieved from this clear-text…

  • CVE-2024-33616MedNov 26, 2024
    risk 0.35cvss 5.3epss 0.01

    Admin authentication can be bypassed with some specific invalid credentials, which allows logging in with an administrative privilege. Sharp Corporation states the telnet feature is implemented on older models only, and is planning to provide the firmware update to remove the…

  • CVE-2024-47864MedDec 23, 2024
    risk 0.34cvss 5.3epss 0.01

    home 5G HR02, Wi-Fi STATION SH-52B, and Wi-Fi STATION SH-54C contain a buffer overflow vulnerability in the hidden debug function. A remote unauthenticated attacker may get the web console of the product down.

  • CVE-2024-45842MedOct 25, 2024
    risk 0.34cvss 5.3epss 0.01

    Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability. Unintended internal files may be retrieved when processing crafted HTTP requests.

  • CVE-2024-45302MedAug 29, 2024
    risk 0.33cvss 6.1epss 0.00

    RestSharp is a Simple REST and HTTP API Client for .NET. The second argument to `RestRequest.AddHeader` (the header value) is vulnerable to CRLF injection. The same applies to `RestRequest.AddOrUpdateHeader` and `RestClient.AddDefaultHeader`. The way HTTP headers are added to a…

  • CVE-2024-45829MedOct 25, 2024
    risk 0.32cvss 4.9epss 0.01

    Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability. Crafted HTTP requests may cause affected products crashed.

  • CVE-2017-10890MedNov 17, 2017
    risk 0.30cvss 4.6epss 0.00

    Session management issue in RX-V200 firmware versions prior to 09.87.17.09, RX-V100 firmware versions prior to 03.29.17.09, RX-CLV1-P firmware versions prior to 79.17.17.09, RX-CLV2-B firmware versions prior to 89.07.17.09, RX-CLV3-N firmware versions prior to 91.09.17.10 allows…

  • CVE-2023-38302MedApr 22, 2024
    risk 0.28cvss 4.3epss 0.00

    A certain software build for the Sharp Rouvo V device (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys) leaks the Wi-Fi MAC address and the Bluetooth MAC address to system properties that can be accessed by any local app on the device without any…

  • CVE-2016-1175MedApr 5, 2016
    risk 0.28cvss 4.3epss 0.01

    Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users.

  • CVE-2019-12762MedJun 6, 2019
    risk 0.27cvss 4.2epss 0.00

    Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.

  • CVE-2023-38301LowApr 22, 2024
    risk 0.22cvss 3.4epss 0.00

    An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers. Various software builds for the BLU View 2, Boost Mobile Celero 5G, Sharp Rouvo V, Motorola Moto G Pure, Motorola Moto G Power, T-Mobile Revvl…

  • CVE-2026-63563MedAug 3, 2026
    risk 0.00cvss 6.5epss 0.00

    Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document…

  • CVE-2026-63545LowAug 3, 2026
    risk 0.00cvss 2.4epss 0.00

    Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.

  • CVE-2026-60011MedAug 3, 2026
    risk 0.00cvss 5.3epss 0.00

    Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.

  • CVE-2014-7252Dec 5, 2014
    risk 0.00cvss epss 0.00

    Multiple unspecified vulnerabilities in the Syslink driver for Texas Instruments OMAP mobile processor, as used on NTT DOCOMO ARROWS Tab LTE F-01D, ARROWS X LTE F-05D, Disney Mobile on docomo F-08D, REGZA Phone T-01D, and PRADA phone by LG L-02D; and SoftBank SHARP handsets…

  • CVE-2013-3655Jul 12, 2013
    risk 0.00cvss epss 0.02

    The Sharp AQUOS PhotoPlayer HN-PP150 with firmware before 1.04.00.04 allows remote attackers to cause a denial of service (networking outage) via crafted packet data.

  • CVE-2002-1974Dec 31, 2002
    risk 0.00cvss epss 0.03

    The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.

Page 2 of 2