mobile devices
CVEs (1,006)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30716 | Med | 0.26 | 4.0 | 0.00 | Sep 6, 2023 | Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to trigger certain commands. | ||
| CVE-2023-30715 | Med | 0.26 | 4.0 | 0.00 | Sep 6, 2023 | Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission. | ||
| CVE-2023-30711 | Med | 0.26 | 4.0 | 0.00 | Sep 6, 2023 | Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider. | ||
| CVE-2023-30707 | Med | 0.26 | 4.0 | 0.00 | Sep 6, 2023 | Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege. | ||
| CVE-2023-21495 | Med | 0.26 | 4.0 | 0.00 | May 4, 2023 | Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set. | ||
| CVE-2023-21461 | Med | 0.26 | 4.0 | 0.00 | Mar 16, 2023 | Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity. | ||
| CVE-2023-21449 | Med | 0.26 | 4.0 | 0.00 | Mar 16, 2023 | Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission. | ||
| CVE-2023-21437 | Med | 0.26 | 4.0 | 0.00 | Feb 9, 2023 | Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast. | ||
| CVE-2023-21429 | Med | 0.26 | 4.0 | 0.00 | Feb 9, 2023 | Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID. | ||
| CVE-2023-21428 | Med | 0.26 | 4.0 | 0.00 | Feb 9, 2023 | Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code. | ||
| CVE-2022-39914 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2022 | Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information. | ||
| CVE-2022-39905 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2022 | Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent. | ||
| CVE-2022-39903 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2022 | Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number. | ||
| CVE-2022-39898 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2022 | Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim. | ||
| CVE-2022-39896 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2022 | Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent. | ||
| CVE-2022-39895 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2022 | Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent. | ||
| CVE-2022-39894 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2022 | Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent. | ||
| CVE-2022-39883 | Med | 0.26 | 4.0 | 0.00 | Nov 9, 2022 | Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API. | ||
| CVE-2022-39856 | Med | 0.26 | 4.0 | 0.00 | Oct 7, 2022 | Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call information. | ||
| CVE-2022-39851 | Med | 0.26 | 4.0 | 0.00 | Oct 7, 2022 | Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission. |
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to trigger certain commands.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.
- risk 0.26cvss 4.0epss 0.00
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
- risk 0.26cvss 4.0epss 0.00
Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
- risk 0.26cvss 4.0epss 0.00
Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.
- risk 0.26cvss 4.0epss 0.00
Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
- risk 0.26cvss 4.0epss 0.00
Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.
- risk 0.26cvss 4.0epss 0.00
Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.
- risk 0.26cvss 4.0epss 0.00
Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
- risk 0.26cvss 4.0epss 0.00
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call information.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.
Page 43 of 51