Samsung Galaxy S4等都是韩国三星(Samsung)公司发布的智能移动设备。 多款Samsung Galaxy设备的SwiftKey language-pack升级实现过程中存在目录遍历漏洞。远程攻击者可借助skslm.swiftkey.net域名的控制权限和ZIP归档的条目中的目录遍历字符‘..’利用该漏洞写入任意文件,并以提升的权限执行任意代码。以下产品受到影响:Samsung Galaxy S4,S4 Mini,S5,S6。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2015-4191 | Cisco IOS XR 资源管理错误漏洞 | |
| CVE-2015-4194 | Cisco WebEx Meeting Center 信息泄露漏洞 | |
| CVE-2015-4195 | Cisco IOS XR 资源管理错误漏洞 | |
| CVE-2015-2797 | 多款AirTies Air产品基于栈的缓冲区溢出漏洞 | |
| CVE-2015-4640 | 多款Samsung Galaxy设备安全漏洞 | |
| CVE-2015-4675 | Tiny SRP library 缓冲区溢出漏洞 | |
| CVE-2015-4676 | TickFa SQL注入漏洞 | |
| CVE-2015-4677 | FiverrScript 跨站请求伪造漏洞 | |
| CVE-2015-4678 | Persian Car CMS SQL注入漏洞 | |
| CVE-2015-4679 | Airties RT-210 跨站脚本漏洞 |
No comments yet