Samsung
Samsung Sth-eth-250 Firmware: vulnerabilidades y CVE
Samsung Sth-eth-250 Firmware tiene 40 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 19 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses0
Críticas19
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-3915 | Alta (8.2) | 0.40% | — | 21 sept 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call… |
| CVE-2018-3914 | Alta (7.8) | 0.42% | — | 21 sept 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call… |
| CVE-2018-3913 | Media (6.7) | 0.40% | — | 21 sept 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call… |
| CVE-2018-3906 | Alta (8.2) | 0.41% | — | 21 sept 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field in video-core's HTTP server of Samsung SmartThings Hub. The video-core process insecurely extracts the… |
| CVE-2018-3894 | Alta (8.8) | 1.8% | — | 21 sept 2018 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy call overflows the… |
| CVE-2018-3877 | Crítica (9.9) | 1.8% | — | 21 sept 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer,… |
| CVE-2018-3876 | Alta (8.8) | 1.9% | — | 21 sept 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer,… |
| CVE-2018-3874 | Crítica (9.9) | 1.8% | — | 21 sept 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer,… |
| CVE-2018-3873 | Crítica (9.9) | 1.8% | — | 21 sept 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer,… |
| CVE-2018-3865 | Alta (8.8) | 1.8% | — | 20 sept 2018 | An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy overflows the destination… |
| CVE-2018-3864 | Alta (8.8) | 1.8% | — | 20 sept 2018 | An exploitable buffer overflow vulnerability exists in the Samsung WifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy overflows the destination… |
| CVE-2018-3875 | Crítica (9.9) | 1.5% | — | 10 sept 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The video-core process incorrectly extracts… |
| CVE-2018-3897 | Alta (8.8) | 1.5% | — | 10 sept 2018 | An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts… |
| CVE-2018-3896 | Alta (8.8) | 1.5% | — | 10 sept 2018 | An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts… |
| CVE-2018-3916 | Alta (7.8) | 0.39% | — | 28 ago 2018 | An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call… |
| CVE-2018-3908 | Alta (7.5) | 1.3% | — | 28 ago 2018 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests,… |
| CVE-2018-3895 | Alta (8.8) | 1.8% | — | 28 ago 2018 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 Firmware version 0.20.17. The strncpy call overflows the… |
| CVE-2018-3926 | Media (5.5) | 0.42% | — | 28 ago 2018 | An exploitable integer underflow vulnerability exists in the ZigBee firmware update routine of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process incorrectly… |
| CVE-2018-3927 | Media (5.9) | 1.1% | — | 27 ago 2018 | An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. When hubCore crashes, Google Breakpad is used… |
| CVE-2018-3918 | Alta (7.5) | 0.99% | — | 27 ago 2018 | An exploitable vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process listens on port 39500 and relays any unauthenticated messages to… |
| CVE-2018-3904 | Crítica (9.9) | 1.8% | — | 27 ago 2018 | An exploitable buffer overflow vulnerability exists in the camera 'update' feature of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly… |
| CVE-2018-3893 | Alta (8.8) | 1.8% | — | 27 ago 2018 | An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly… |
| CVE-2018-3909 | Alta (8.6) | 1.3% | — | 24 ago 2018 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP… |
| CVE-2018-3907 | Crítica (10) | 1.4% | — | 24 ago 2018 | An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP… |
| CVE-2018-3911 | Alta (8.6) | 1.2% | — | 23 ago 2018 | An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process listens on port 39500 and relays any unauthenticated… |
| CVE-2018-3880 | Crítica (9.9) | 1.2% | — | 23 ago 2018 | An exploitable stack-based buffer overflow vulnerability exists in the database 'find-by-cameraId' functionality of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The… |
| CVE-2018-3872 | Crítica (9.9) | 1.8% | — | 23 ago 2018 | An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extracts… |
| CVE-2018-3866 | Crítica (9.9) | 1.5% | — | 23 ago 2018 | An exploitable buffer overflow vulnerability exists in the samsungWifiScan handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly… |
| CVE-2018-3856 | Crítica (9.9) | 3.4% | — | 23 ago 2018 | An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The device incorrectly handles spaces in the URL field, leading to an… |
| CVE-2018-3912 | Alta (7.8) | 0.40% | — | 23 ago 2018 | On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process insecurely extracts the fields from the "shard" table of its SQLite database, leading to a buffer overflow on the… |