Vulnerabilities > Samsung > Medium

DATE CVE VULNERABILITY TITLE RISK
2013-10-01 CVE-2013-3964 Cross-Site Scripting vulnerability in Samsung Shr-5082 and Shr-5162
Cross-site scripting (XSS) vulnerability in Samsung SHR-5162, SHR-5082, and possibly other models, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
network
samsung CWE-79
4.3
2013-08-28 CVE-2013-3585 Credentials Management vulnerability in Samsung Smart Viewer
Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page.
network
low complexity
samsung CWE-255
5.0
2012-12-03 CVE-2012-5859 Denial of Service and Security Bypass vulnerability in Samsung Kies AIR 2.1.207051/2.1.210161
Samsung Kies Air 2.1.207051 and 2.1.210161 allows remote attackers to cause a denial of service (crash) via a crafted request to www/apps/KiesAir/jws/ssd.php.
network
low complexity
samsung
5.0
2012-12-03 CVE-2012-5858 Improper Authentication vulnerability in Samsung Kies AIR 2.1.207051/2.1.210161
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitrary phone contents by spoofing or controlling the IP address.
network
samsung CWE-287
4.3
2007-07-21 CVE-2007-3931 Local Privilege Escalation vulnerability in Samsung Scx-4200 Driver 2.00.95
The wrap_setuid_third_party_application function in the installation script for the Samsung SCX-4200 Driver 2.00.95 adds setuid permissions to third party applications such as xsane and xscanimage, which allows local users to gain privileges.
local
samsung
4.4
2001-07-17 CVE-2001-1177 Unspecified vulnerability in Samsung Ml-85G GDI Printer Driver and Ml-85P Printer Driver
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
local
high complexity
samsung
6.2