Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 0.40% | — | Samsung Sth-eth-250 Firmware | 21/9/2018 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 64 bytes. An attacker can send an arbitrarily… | |
| Modificada | Alta (7.8) | 0.42% | — | Samsung Sth-eth-250 Firmware | 21/9/2018 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 2000 bytes. An attacker can send an arbitrarily… | |
| Modificada | Media (6.7) | 0.40% | — | Samsung Sth-eth-250 Firmware | 21/9/2018 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 32 bytes. An attacker can send an arbitrarily… | |
| Modificada | Alta (8.2) | 0.41% | — | Samsung Sth-eth-250 Firmware | 21/9/2018 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field in video-core's HTTP server of Samsung SmartThings Hub. The video-core process insecurely extracts the shard.videoHostURL field from its SQLite database, leading to a buffer overflow on the stack. An attacker can send… | |
| Modificada | Alta (8.8) | 1.8% | — | Samsung Sth-eth-250 Firmware | 21/9/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long "startTime" value… | |
| Modificada | Crítica (9.9) | 1.8% | — | Samsung Sth-eth-250 Firmware | 21/9/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 160 bytes. An attacker can send an arbitrarily long "directory" value in order to… | |
| Modificada | Alta (8.8) | 1.9% | — | Samsung Sth-eth-250 Firmware | 21/9/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 64 bytes. An attacker can send an arbitrarily long "bucket" value in order to… | |
| Modificada | Crítica (9.9) | 1.8% | — | Samsung Sth-eth-250 Firmware | 21/9/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 32 bytes. An attacker can send an arbitrarily long "accessKey" value in order to… | |
| Modificada | Crítica (9.9) | 1.8% | — | Samsung Sth-eth-250 Firmware | 21/9/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey" value in order to… | |
| Modificada | Alta (8.8) | 1.8% | — | Samsung Sth-eth-250 Firmware | 20/9/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy overflows the destination buffer, which has a size of 40 bytes. An attacker can send an arbitrarily long "cameraIp" value in… | |
| Modificada | Alta (8.8) | 1.8% | — | Samsung Sth-eth-250 Firmware | 20/9/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy overflows the destination buffer, which has a size of 40 bytes. An attacker can send an arbitrarily long "password" value in… | |
| Modificada | Crítica (9.9) | 1.5% | — | Samsung Sth-eth-250 Firmware | 10/9/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strncpy… | |
| Modificada | Alta (8.8) | 1.5% | — | Samsung Sth-eth-250 Firmware | 10/9/2018 | 17/6/2026 | An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strncpy… | |
| Modificada | Alta (8.8) | 1.5% | — | Samsung Sth-eth-250 Firmware | 10/9/2018 | 17/6/2026 | An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strncpy… | |
| Modificada | Alta (7.8) | 0.39% | — | Samsung Sth-eth-250 Firmware | 28/8/2018 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 136 bytes. An attacker can send an arbitrarily… | |
| Modificada | Alta (7.5) | 1.3% | — | Samsung Sth-eth-250 Firmware | 28/8/2018 | 17/6/2026 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method, URL and body. With… | |
| Modificada | Alta (8.8) | 1.8% | — | Samsung Sth-eth-250 Firmware | 28/8/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 Firmware version 0.20.17. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long 'endTime' value… | |
| Modificada | Media (5.5) | 0.42% | — | Samsung Sth-eth-250 Firmware | 28/8/2018 | 17/6/2026 | An exploitable integer underflow vulnerability exists in the ZigBee firmware update routine of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process incorrectly handles malformed files existing in its data directory, leading to an infinite loop, which eventually… | |
| Modificada | Media (5.9) | 1.1% | — | Samsung Sth-eth-250 Firmware | 27/8/2018 | 17/6/2026 | An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. When hubCore crashes, Google Breakpad is used to record minidumps, which are sent over an insecure HTTPS connection to the backtrace.io service,… | |
| Modificada | Alta (7.5) | 0.99% | — | Samsung Sth-eth-250 Firmware | 27/8/2018 | 17/6/2026 | An exploitable vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process listens on port 39500 and relays any unauthenticated messages to SmartThings' remote servers, which incorrectly handle camera IDs for the 'sync' operation, leading to… | |
| Modificada | Crítica (9.9) | 1.8% | — | Samsung Sth-eth-250 Firmware | 27/8/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the camera 'update' feature of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An… | |
| Modificada | Alta (8.8) | 1.8% | — | Samsung Sth-eth-250 Firmware | 27/8/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An… | |
| Modificada | Alta (8.6) | 1.3% | — | Samsung Sth-eth-250 Firmware | 24/8/2018 | 17/6/2026 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method,… | |
| Modificada | Crítica (10) | 1.4% | — | Samsung Sth-eth-250 Firmware | 24/8/2018 | 17/6/2026 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the previously parsed HTTP method, 'on_url'… | |
| Modificada | Alta (8.6) | 1.2% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process listens on port 39500 and relays any unauthenticated message to SmartThings' remote servers, which insecurely handle JSON messages, leading to partially… |