Total vulnerabilities in the database
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
Software | From | Fixed in |
---|---|---|
w1.fi / hostapd | - | 2.0.0 |
hp / envy_5000_m2u91a | - | - |
microsoft / xbox_one | 10.0.19041.2494 | 10.0.19041.2494.x |
fedoraproject / fedora | 31 | 31.x |
fedoraproject / fedora | 32 | 32.x |
debian / debian_linux | 9.0 | 9.0.x |
debian / debian_linux | 10.0 | 10.0.x |
canonical / ubuntu_linux | 20.04 | 20.04.x |