Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.9) | 1.2% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles existing records inside its SQLite database, leading to a buffer… | |
| Modificada | Crítica (9.9) | 1.8% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extracts the videoHostUrl field from a user-controlled JSON payload, leading to a buffer overflow on the… | |
| Modificada | Crítica (9.9) | 1.5% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strcpy… | |
| Modificada | Crítica (9.9) | 3.4% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The device incorrectly handles spaces in the URL field, leading to an arbitrary operating system command injection. An attacker can send a series of HTTP requests to… | |
| Modificada | Alta (7.8) | 0.40% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts the fields from the "shard" table of its SQLite database, leading to a buffer overflow on the stack. The strcpy call overflows the destination buffer, which has a size of 128 bytes. An attacker can… | |
| Modificada | Crítica (9.9) | 1.5% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the remote video-host communication of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process insecurely parses the AWSELB cookie while communicating with remote video-host servers, leading to… | |
| Modificada | Crítica (9.9) | 0.95% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process insecurely extracts the fields from the "clips" table of its SQLite database, leading to a… | |
| Modificada | Crítica (9.9) | 0.95% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts the fields from the "shard" table of its SQLite database, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. The strcpy call overflows the… | |
| Modificada | Crítica (9.9) | 1.5% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the camera "create" feature of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly extracts the "state" field from a user-controlled JSON payload, leading to a buffer overflow on… | |
| Modificada | Crítica (9.9) | 1.8% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. The memcpy call overflows the destination… | |
| Modificada | Crítica (9.9) | 1.8% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the camera "replace" feature of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly extracts the URL field from a user-controlled JSON payload, leading to a buffer overflow on… | |
| Modificada | Alta (8.8) | 1.6% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly parses the user-controlled JSON payload, leading to a JSON injection which in turn leads to a SQL… | |
| Modificada | Crítica (9.9) | 1.5% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the… | |
| Modificada | Crítica (9.9) | 2.0% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly handles the answer received from a smart camera, leading to a buffer… | |
| Modificada | Crítica (9.9) | 1.7% | — | Samsung Sth-eth-250 Firmware | 23/8/2018 | 17/6/2026 | On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. A strcpy overflows the destination buffer,… |