2024-11-23 01:05:45 +00:00

100 lines
3.1 KiB
JSON

{
"id": "CVE-2015-8039",
"sourceIdentifier": "cve@mitre.org",
"published": "2015-11-02T19:59:19.177",
"lastModified": "2024-11-21T02:37:54.070",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors to the (1) DVRSetupSave method in the STWAxConfig control or (2) SendCustomPacket method in the STWAxConfigNVR control, which trigger an untrusted pointer dereference."
},
{
"lang": "es",
"value": "Samsung SmartViewer permite que los atacantes remotos ejecuten c\u00f3digo arbitrario mediante vectores sin especificar en (1) el m\u00e9todo DVRSetupSave en el control STWAxConfig o (2) el m\u00e9todo SendCustomPacket en el control STWAxConfigNVR, lo que desencadena una desreferencia de puntero no fiable."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"baseScore": 6.8,
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:samsung:smartviewer:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B9D3173B-53C9-4A0F-B580-609880B4B386"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/77079",
"source": "cve@mitre.org"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-15-462",
"source": "cve@mitre.org"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-15-463",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/77079",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-15-462",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.zerodayinitiative.com/advisories/ZDI-15-463",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"evaluatorComment": "<a href=\"http://cwe.mitre.org/data/definitions/476.html\">CWE-476: NULL Pointer Dereference</a>"
}