Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

X14j Firmware MEDIUM 6.5
CVE-2016-1308

SQL injection vulnerability in Cisco Unified Communications Manager 10.5(2.13900.9) allows remote authenticated users to execute arbitrary SQL comman…

Mitigation only
Fix from $1,600 2016-02-07
Web Viewer HIGH 7.5
CVE-2015-8281

Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows attackers to bypass filesystem encryption via XOR calculations.

Fix: after 1.0.0.193
Fix from $1,950 2016-01-15
Web Viewer HIGH 7.5
CVE-2015-8280EPSS 6%

Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to discover credentials by reading detailed error messages.

Fix: after 1.0.0.193
Fix from $1,950 2016-01-15
Web Viewer HIGH 8.6
CVE-2015-8279EPSS 51%

Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to read arbitrary files via a request to an unspecified PHP script.

Fix: after 1.0.0.193
Fix from $1,950 2016-01-15
Galaxy S6 HIGH 7.5
CVE-2015-7897EPSS 7%

The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remot…

No fix yet
Fix from $1,950 2015-11-16
Smartviewer MEDIUM 6.8
CVE-2015-8040

The rtsp_getdlsendtime method in the CNC_Ctrl control in Samsung SmartViewer allows remote attackers to execute arbitrary code via an index value.

Mitigation only
Fix from $1,600 2015-11-02
Smartviewer MEDIUM 6.8
CVE-2015-8039

Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors to the (1) DVRSetupSave method in the STWAxConfig contr…

Mitigation only
Fix from $1,600 2015-11-02
Galaxy S5 HIGH 7.9
CVE-2015-4034

The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2015-07-06
Samsung Security Manager HIGH 10.0
CVE-2015-3435EPSS 10%

Samsung Security Manager (SSM) before 1.31 allows remote attackers to execute arbitrary code by uploading a file with an HTTP (1) PUT or (2) MOVE req…

Fix: after 1.30
Fix from $1,950 2015-05-01
Ipolis Device Manager MEDIUM 6.8
CVE-2015-0555EPSS 6%

Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitra…

No fix yet
Fix from $1,600 2015-02-24
Samsung Security Manager HIGH 8.5
CVE-2015-1499

The ActiveMQ Broker in Samsung Security Manager (SSM) before 1.31 allows remote attackers to delete arbitrary files, and consequently cause a denial …

Fix: after 1.30
Fix from $1,950 2015-02-16
Smart Viewer MEDIUM 6.8
CVE-2014-9266

The STWConfig ActiveX control in Samsung SmartViewer does not properly initialize a variable, which allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,600 2014-12-08
Smartviewer MEDIUM 6.8
CVE-2014-9265

Stack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remote attackers to execute arbit…

Mitigation only
Fix from $1,600 2014-12-08
Findmymobile HIGH 7.8
CVE-2014-8346

The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier f…

No fix yet
Fix from $1,950 2014-10-24
Ipolis Device Manager HIGH 9.3
CVE-2014-3911EPSS 6%

Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeContro…

Fix: after 1.8.2
Fix from $1,950 2014-06-11
Ipolis Device Manager HIGH 9.3
CVE-2014-3912

Stack-based buffer overflow in the FindConfigChildeKeyList method in the XNSSDKDEVICE.XnsSdkDeviceCtrlForIpInstaller.1 ActiveX control in Samsung iPO…

Fix: after 1.8.2
Fix from $1,950 2014-06-05
Kies HIGH 10.0
CVE-2012-6429EPSS 15%

Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to ex…

Fix: after 2.5.0.12114_1
Fix from $1,950 2014-04-04
Smart Viewer HIGH 7.6
CVE-2013-3586EPSS 11%

Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.

Mitigation only
Fix from $1,950 2013-08-28
Smart Viewer MEDIUM 5.0
CVE-2013-3585EPSS 24%

Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information …

Mitigation only
Fix from $1,600 2013-08-28
Ps50c7700 Television Firmware HIGH 7.8
CVE-2013-4890

The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon crash) via a long URI to TCP port…

No fix yet
Fix from $1,950 2013-07-23
Kies Air MEDIUM 5.0
CVE-2012-5859

Samsung Kies Air 2.1.207051 and 2.1.210161 allows remote attackers to cause a denial of service (crash) via a crafted request to www/apps/KiesAir/jws…

No fix yet
Fix from $1,600 2012-12-03
Printer Firmware HIGH 7.5
CVE-2012-4964EPSS 8%

The Samsung printer firmware before 20121031 has a hardcoded read-write SNMP community, which makes it easier for remote attackers to obtain administ…

Fix: after 20121030
Fix from $1,950 2012-11-28
Kies HIGH 9.3
CVE-2012-2990

The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.12074…

Fix: after 2.3.2.12074
Fix from $1,950 2012-08-24
Net I Viewer HIGH 10.0
CVE-2012-4333EPSS 60%

Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung …

Mitigation only
Fix from $1,950 2012-08-14
Net I Viewer HIGH 10.0
CVE-2012-4334EPSS 7%

The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remo…

Mitigation only
Fix from $1,950 2012-08-14
D6000 Firmware HIGH 7.8
CVE-2012-4329EPSS 13%

The Samsung D6000 TV and possibly other products allow remote attackers to cause a denial of service (continuous restart) via a crafted controller na…

No fix yet
Fix from $1,950 2012-08-14
D6000 Firmware HIGH 7.8
CVE-2012-4330EPSS 14%

The Samsung D6000 TV and possibly other products allows remote attackers to cause a denial of service (crash) via a long string in certain fields, as…

No fix yet
Fix from $1,950 2012-08-14
Net I Viewer HIGH 7.8
CVE-2012-4335

Samsung NET-i viewer 1.37.120316 allows remote attackers to cause a denial of service (infinite loop) via a negative size value in a TCP request to (…

No fix yet
Fix from $1,950 2012-08-14
Net I Viewer HIGH 9.3
CVE-2012-4250EPSS 6%

Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewe…

No fix yet
Fix from $1,950 2012-08-13
Data Management Server HIGH 7.5
CVE-2010-4284

SQL injection vulnerability in the authentication form in the integrated web server in the Data Management Server (DMS) before 1.4.3 in Samsung Integ…

Fix: after 1.4.2
Fix from $1,950 2011-05-09