VYPR

Galaxy Gear

by Samsung Mobile

CVEs (5)

  • CVE-2018-16263HigJan 22, 2020
    risk 0.57cvss 8.8epss 0.01

    The PulseAudio system service in Tizen allows an unprivileged process to control its A2DP MediaEndpoint, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.

  • CVE-2018-16267HigJan 22, 2020
    risk 0.53cvss 8.1epss 0.01

    The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations. Such actions include the triggering system poweroff menu, and prompting a popup with arbitrary strings. This…

  • CVE-2018-16271MedJan 22, 2020
    risk 0.42cvss 6.5epss 0.01

    The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the…

  • CVE-2018-16264MedJan 22, 2020
    risk 0.42cvss 6.5epss 0.01

    The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive information, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear…

  • CVE-2018-16268MedJan 22, 2020
    risk 0.28cvss 4.3epss 0.01

    The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This affects Tizen before 5.0 M1,…

VYPR — Vulnerability Intelligence