Vulnerability Description
Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors to the (1) DVRSetupSave method in the STWAxConfig control or (2) SendCustomPacket method in the STWAxConfigNVR control, which trigger an untrusted pointer dereference.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Samsung | Smartviewer | - |
References
- http://www.securityfocus.com/bid/77079
- http://www.zerodayinitiative.com/advisories/ZDI-15-462
- http://www.zerodayinitiative.com/advisories/ZDI-15-463
- http://www.securityfocus.com/bid/77079
- http://www.zerodayinitiative.com/advisories/ZDI-15-462
- http://www.zerodayinitiative.com/advisories/ZDI-15-463
FAQ
What is CVE-2015-8039?
CVE-2015-8039 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Samsung SmartViewer allows remote attackers to execute arbitrary code via unspecified vectors to the (1) DVRSetupSave method in the STWAxConfig control or (2) SendCustomPacket method in the STWAxConfi...
How severe is CVE-2015-8039?
CVE-2015-8039 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-8039?
Check the references section above for vendor advisories and patch information. Affected products include: Samsung Smartviewer.