Page 4 of 17 results (0.003 seconds)

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 1

Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter. Múltiples desbordamientos de búfer en la función esa_write en el archivo /dev/seirenin en el controlador Exynos Seiren Audio, como es usado en Samsung S6 Edge, permiten a usuarios locales causar una denegación de servicio (corrupción de memoria) por medio de un parámetro (1) buffer o (2) size de gran tamaño • https://www.exploit-db.com/exploits/38556 http://packetstormsecurity.com/files/134106/Samsung-Seiren-Kernel-Driver-Buffer-Overflow.html https://code.google.com/p/google-security-research/issues/detail?id=491 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a .. (dot dot) in the name of a file, compressed into a zipped file named cred.zip, and downloaded to /sdcard/Download. Vulnerabilidad de salto de directorio en WifiHs20UtilityService en el Samsung S6 Edge LRX22G.G925VVRU1AOE2, permite a atacantes remotos sobrescribir o crear archivos arbitrarios como un usuario a nivel de sistema a través de .. (punto punto) en un archivo comprimido en Cred.zip, y descargado en /sdcard/Download. A path traversal vulnerability was found in the WifiHs20UtilityService. • http://packetstormsecurity.com/files/134104/Samsung-WifiHs20UtilityService-Path-Traversal.html http://www.securityfocus.com/bid/77338 https://bugs.chromium.org/p/project-zero/issues/detail?id=489&q=samsung&redir=1 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •