mobile devices
CVEs (991)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-34650 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel. | ||
| CVE-2024-34647 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license. | ||
| CVE-2024-34618 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information. | ||
| CVE-2024-34617 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application. | ||
| CVE-2024-34613 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch. | ||
| CVE-2024-34603 | Med | 0.26 | 4.0 | 0.00 | Jul 8, 2024 | Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data. | ||
| CVE-2024-34583 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier. | ||
| CVE-2024-20900 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication. | ||
| CVE-2024-20899 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20898 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20897 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20879 | Med | 0.26 | 4.0 | 0.00 | Jun 4, 2024 | Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2024-20875 | Med | 0.26 | 4.0 | 0.00 | Jun 4, 2024 | Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files. | ||
| CVE-2024-20860 | Med | 0.26 | 4.0 | 0.00 | May 7, 2024 | Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission. | ||
| CVE-2024-20858 | Med | 0.26 | 4.0 | 0.00 | May 7, 2024 | Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application. | ||
| CVE-2024-20857 | Med | 0.26 | 4.0 | 0.00 | May 7, 2024 | Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application. | ||
| CVE-2024-20848 | Med | 0.26 | 4.0 | 0.00 | Apr 2, 2024 | Improper Input Validation vulnerability in text parsing implementation of libsdffextractor prior to SMR Apr-2024 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2024-20847 | Med | 0.26 | 4.0 | 0.00 | Apr 2, 2024 | Improper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allows local attackers to read sdcard information. | ||
| CVE-2024-20835 | Med | 0.26 | 4.0 | 0.00 | Mar 5, 2024 | Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local attackers to execute privileged behaviors. | ||
| CVE-2024-20814 | Med | 0.26 | 4.0 | 0.00 | Feb 6, 2024 | Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information. |
- risk 0.26cvss 4.0epss 0.00
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
- risk 0.26cvss 4.0epss 0.00
Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.
- risk 0.26cvss 4.0epss 0.00
Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.
- risk 0.26cvss 4.0epss 0.00
Improper access control in Galaxy Watch prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive information of Galaxy watch.
- risk 0.26cvss 4.0epss 0.00
Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.
- risk 0.26cvss 4.0epss 0.00
Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.
- risk 0.26cvss 4.0epss 0.00
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files.
- risk 0.26cvss 4.0epss 0.00
Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.
- risk 0.26cvss 4.0epss 0.00
Improper Input Validation vulnerability in text parsing implementation of libsdffextractor prior to SMR Apr-2024 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Improper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allows local attackers to read sdcard information.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local attackers to execute privileged behaviors.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.
Page 41 of 50