← Back

Sony

sony

74 CVEs • 413 products

Products (413)

Click to collapse
Toggle
R5c Firmware
r5c_firmware
Wd75 Firmware
wd75_firmware
Wd65 Firmware
wd65_firmware
Xe70 Firmware
xe70_firmware
Xf70 Firmware
xf70_firmware
We75 Firmware
we75_firmware
We6 Firmware
we6_firmware
Wf6 Firmware
wf6_firmware
Playstation 3
playstation_3
Music Center
music_center
Vaio Update
vaio_update
P900 Firmware
p900_firmware
Imagestation
imagestation
Mylo Com 2
mylo_com_2
Bravia Tv
bravia_tv
Sound Forge
sound_forge
Moviez Hd
moviez_hd
Snc Ch140
snc_ch140
Snc Ch180
snc_ch180
Snc Ch240
snc_ch240
Snc Ch280
snc_ch280
Snc Dh140
snc_dh140
Snc Dh140t
snc_dh140t
Snc Dh180
snc_dh180
Snc Dh240
snc_dh240
Snc Dh240t
snc_dh240t
Snc Dh280
snc_dh280
Media Go
media_go

CVEs (74)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sony
1Mylo Com 2
Apr 23, 2026
Apr 25, 2008
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Sony Mylo COM-2 Japanese model firmware before 1.002 does not properly verify web server SSL certificates, which allows remote attackers to obtain sensitive information and conduct spoofing attacks.
1Sony
2Axruploadserver Activex Control
Imagestation
Apr 23, 2026
Feb 13, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a lo...Show more
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method. NOTE: some of these details are obtained from third party information.Show less
1Sony
1Sonicstage Connect Player
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file name in an M3U file.
1Sony
1Micro Vault Fingerprint Access Software
Apr 23, 2026
Sep 10, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Sony Micro Vault Fingerprint Access Software, as distributed with Sony Micro Vault USM-F USB flash drives, installs a driver that hides a directory under %WINDIR%, which might allow remote attackers to bypass malware det...Show more
Sony Micro Vault Fingerprint Access Software, as distributed with Sony Micro Vault USM-F USB flash drives, installs a driver that hides a directory under %WINDIR%, which might allow remote attackers to bypass malware detection by placing files in this directory.Show less
1Sony
1Sony Network Camera Snc P5
Apr 23, 2026
Jun 29, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N and SNC-DF70N before 1.18; SNC-RZ50N and...Show more
Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N and SNC-DF70N before 1.18; SNC-RZ50N and SNC-CS50N before 2.22; SNC-DF85N, SNC-DF80N, and SNC-DF50N before 1.12; and SNC-RX570N/W, SNC-RX570N/B, SNC-RX550N/W, SNC-RX550N/B, SNC-RX530N/W, and SNC-RX530N/B 3.00 and 2.x before 2.31; allows remote attackers to execute arbitrary code via a long first argument to the PrmSetNetworkParam method.Show less
1Sony
2Playstation 3
Playstation Portable
Apr 23, 2026
Mar 28, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
The Remote Play feature in Sony Playstation 3 (PS3) 1.60 and Playstation Portable (PSP) 3.10 OE-A allows remote attackers to cause a denial of service via a flood of UDP packets.
1Sony
1Playstation Portable
Apr 16, 2026
Aug 31, 2006
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unspecified vulnerability in the TIFF viewer (possibly libTIFF) in the Photo Viewer in the Sony PlaystationPortable (PSP) 2.00 through 2.80 allows local users to execute arbitrary code via crafted TIFF images. NOTE: due...Show more
Unspecified vulnerability in the TIFF viewer (possibly libTIFF) in the Photo Viewer in the Sony PlaystationPortable (PSP) 2.00 through 2.80 allows local users to execute arbitrary code via crafted TIFF images. NOTE: due to lack of details, it is not clear whether this is related to other issues such as CVE-2006-3464 or CVE-2006-3465.Show less
1Sony
1Vaio Media Server
Apr 16, 2026
Aug 22, 2006
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to gain sensitive information via unspecified vectors.
1Sony
1Vaio Media Server
Apr 16, 2026
Aug 22, 2006
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to execute arbitrary code via unspecified vectors.
1Sony
1Sonicstage Mastering Studio
Apr 16, 2026
Aug 21, 2006
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the import project functionality in Sony SonicStage Mastering Studio 1.1.00 through 2.2.01 allows remote attackers to execute arbitrary code via a crafted SMP file.
1Sony
1First4internet Xcp Content Management
Apr 16, 2026
Nov 3, 2005
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The aries.sys driver in Sony First4Internet XCP DRM software hides any file, registry key, or process with a name that starts with "$sys$", which allows attackers to hide activities on a system that uses XCP.
1Sony
1Playstation Portable
Apr 16, 2026
Sep 27, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the TIFF library in the Photo Viewer for Sony PSP 2.0 firmware allows remote attackers to cause a denial of service via a crafted TIFF image.
1Sony
1P900 Firmware
Apr 16, 2026
Jun 1, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Sony Ericsson P900 Beamer allows remote attackers to cause a denial of service (panic) via an obexftp session with a long filename in an OBEX File Transfer or OBEX Object Push.
1Sony
1Vaio Manual Cybersupport
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unknown vulnerability in the "VAIO Manual" software in certain Sony VAIO personal computers sold from November 2001 to January 2002, allows remote attackers to modify data via a web page or HTML e-mail.