Skip to main content

Vendor archive

geovision CVEs

Beta · best-effort

27 CVEs tagged to vendor geovision12 Critical, 7 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-7372

Published May 4, 2026

A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execu…

CVSS 9.0 · Critical
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-7161

Published May 4, 2026

An insufficient encryption vulnerability exists in the Device Authentication functionality of GeoVision GV-IP Device Utility 9.0.5. Listening to broadcast packets can lead to cred…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-42370

Published May 4, 2026

A stack overflow vulnerability exists in the WebCam Server Login functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted HTTP request can lead to an arbitrary code execu…

CVSS 9.0 · Critical
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2024-12553

Published Dec 13, 2024

GeoVision GV-ASManager Missing Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected install…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11120

Published Nov 15, 2024

Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system co…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
45.4
KEV listed

CVE-2023-23059

Published May 4, 2023

An issue was discovered in GeoVision GV-Edge Recording Manager 2.2.3.0 for windows, which contains improper permissions within the default installation and allows attackers to exe…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-3931

Published Jul 8, 2020

Buffer overflow exists in Geovision Door Access Control device family, an unauthenticated remote attacker can execute arbitrary command.

CVSS 9.8 · Critical

CVE-2009-5087

Published Sep 12, 2011

Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1092

Published Mar 25, 2009

Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by ca…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0865

Published Mar 10, 2009

Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-1552

Published May 14, 2005

GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0, when set to create JPEG images, does not properly protect an image even when a password and username is assigned, wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1553

Published May 14, 2005

GeoVision Digital Video Surveillance System 6.04, 6.1 and 7.0 uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via sniffing.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2