Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-7889 | Med | 0.39 | 5.5 | 0.02 | Dec 28, 2017 | The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge of the local email… | ||
| CVE-2015-7898 | Med | 0.39 | 5.5 | 0.01 | Jun 27, 2017 | Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). | ||
| CVE-2015-7895 | Med | 0.39 | 5.5 | 0.01 | Jun 27, 2017 | Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). | ||
| CVE-2016-1344 | Med | 0.39 | 5.9 | 0.03 | Mar 26, 2016 | The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417. | ||
| CVE-2026-21105 | Med | 0.38 | — | 0.00 | Sep 9, 2026 | Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information. | ||
| CVE-2026-21038 | Med | 0.38 | — | 0.00 | Jun 5, 2026 | Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory. | ||
| CVE-2026-40446 | Med | 0.38 | 6.9 | 0.00 | Apr 13, 2026 | Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335. | ||
| CVE-2025-52517 | Med | 0.38 | 5.9 | 0.00 | Jan 5, 2026 | An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in a double free, leading to a denial of service. | ||
| CVE-2025-58483 | Med | 0.38 | 5.9 | 0.00 | Dec 2, 2025 | Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store. | ||
| CVE-2025-21032 | Med | 0.38 | 5.9 | 0.00 | Sep 3, 2025 | Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions. | ||
| CVE-2023-21468 | Med | 0.38 | 5.9 | 0.00 | Sep 3, 2025 | Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission. | ||
| CVE-2025-32407 | Med | 0.38 | 5.9 | 0.00 | May 16, 2025 | Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate any and all websites visited by the user. This is a critical misconfiguration in the way the browser… | ||
| CVE-2025-20892 | Med | 0.38 | 5.9 | 0.00 | Feb 4, 2025 | Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-49410 | Med | 0.38 | 5.9 | 0.00 | Dec 3, 2024 | Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code. | ||
| CVE-2024-34678 | Med | 0.38 | 5.9 | 0.00 | Nov 6, 2024 | Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. | ||
| CVE-2024-25074 | Med | 0.38 | 5.9 | 0.00 | Sep 10, 2024 | An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123,… | ||
| CVE-2024-25073 | Med | 0.38 | 5.9 | 0.00 | Sep 10, 2024 | An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123,… | ||
| CVE-2024-34601 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore. | ||
| CVE-2024-34596 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner. | ||
| CVE-2024-34586 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy. | ||
| CVE-2024-20901 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2024-20889 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices. | ||
| CVE-2024-28818 | Med | 0.38 | 5.9 | 0.00 | Jun 5, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly… | ||
| CVE-2024-29152 | Med | 0.38 | 5.9 | 0.00 | Jun 4, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos Modem 5123, and Exynos Modem 5300. The baseband software does not properly… | ||
| CVE-2024-20854 | Med | 0.38 | 5.9 | 0.00 | Apr 2, 2024 | Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data. | ||
| CVE-2024-20852 | Med | 0.38 | 5.9 | 0.00 | Apr 2, 2024 | Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration. | ||
| CVE-2024-20846 | Med | 0.38 | 5.9 | 0.00 | Apr 2, 2024 | Out-of-bounds write vulnerability while decoding hcr of libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2023-52432 | Med | 0.38 | 5.9 | 0.00 | Mar 5, 2024 | Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2023-42570 | Med | 0.38 | 5.9 | 0.00 | Dec 5, 2023 | Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN. | ||
| CVE-2023-42538 | Med | 0.38 | 5.9 | 0.00 | Nov 7, 2023 | An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write. | ||
| CVE-2023-42532 | Med | 0.38 | 5.9 | 0.00 | Nov 7, 2023 | Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information. | ||
| CVE-2023-37368 | Med | 0.38 | 5.9 | 0.01 | Sep 8, 2023 | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos Mobile Processor, Automotive Processor, and Modem - Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380,… | ||
| CVE-2023-21455 | Med | 0.38 | 5.9 | 0.00 | Mar 16, 2023 | Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message. | ||
| CVE-2023-21421 | Med | 0.38 | 5.9 | 0.00 | Feb 9, 2023 | Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN. | ||
| CVE-2022-39886 | Med | 0.38 | 5.9 | 0.00 | Nov 9, 2022 | Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information. | ||
| CVE-2022-39885 | Med | 0.38 | 5.9 | 0.00 | Nov 9, 2022 | Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information. | ||
| CVE-2022-39879 | Med | 0.38 | 5.9 | 0.00 | Nov 9, 2022 | Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid. | ||
| CVE-2022-39876 | Med | 0.38 | 5.9 | 0.00 | Oct 7, 2022 | Insertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to access device IMEI. | ||
| CVE-2022-39872 | Med | 0.38 | 5.9 | 0.00 | Oct 7, 2022 | Improper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected Bluetooth device. | ||
| CVE-2022-39861 | Med | 0.38 | 5.9 | 0.00 | Oct 7, 2022 | Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege. | ||
| CVE-2022-36868 | Med | 0.38 | 5.9 | 0.00 | Oct 7, 2022 | Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth device. | ||
| CVE-2022-36874 | Med | 0.38 | 5.9 | 0.00 | Sep 9, 2022 | Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number. | ||
| CVE-2022-36873 | Med | 0.38 | 5.9 | 0.00 | Sep 9, 2022 | Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device. | ||
| CVE-2022-36867 | Med | 0.38 | 5.9 | 0.00 | Sep 9, 2022 | Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information. | ||
| CVE-2022-36861 | Med | 0.38 | 5.9 | 0.00 | Sep 9, 2022 | Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege. | ||
| CVE-2022-36839 | Med | 0.38 | 5.9 | 0.00 | Aug 5, 2022 | SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP information. | ||
| CVE-2022-33729 | Med | 0.38 | 5.9 | 0.00 | Aug 5, 2022 | Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device. | ||
| CVE-2022-30735 | Med | 0.38 | 5.9 | 0.00 | Jun 7, 2022 | Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission. | ||
| CVE-2022-28776 | Med | 0.38 | 5.9 | 0.00 | Apr 11, 2022 | Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions. | ||
| CVE-2022-28541 | Med | 0.38 | 5.9 | 0.00 | Apr 11, 2022 | Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission. |
- risk 0.39cvss 5.5epss 0.02
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge of the local email…
- risk 0.39cvss 5.5epss 0.01
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
- risk 0.39cvss 5.5epss 0.01
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
- risk 0.39cvss 5.9epss 0.03
The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.
- risk 0.38cvss —epss 0.00
Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.
- risk 0.38cvss —epss 0.00
Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.
- risk 0.38cvss 6.9epss 0.00
Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.
- risk 0.38cvss 5.9epss 0.00
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in a double free, leading to a denial of service.
- risk 0.38cvss 5.9epss 0.00
Improper export of android application components in Galaxy Store for Galaxy Watch prior to version 1.0.06.29 allows local attacker to install arbitrary application on Galaxy Store.
- risk 0.38cvss 5.9epss 0.00
Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.
- risk 0.38cvss 5.9epss 0.00
Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.
- risk 0.38cvss 5.9epss 0.00
Samsung Internet for Galaxy Watch version 5.0.9, available up until Samsung Galaxy Watch 3, does not properly validate TLS certificates, allowing for an attacker to impersonate any and all websites visited by the user. This is a critical misconfiguration in the way the browser…
- risk 0.38cvss 5.9epss 0.00
Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. User interaction is required for triggering this vulnerability.
- risk 0.38cvss 5.9epss 0.00
Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.
- risk 0.38cvss 5.9epss 0.00
Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.
- risk 0.38cvss 5.9epss 0.00
An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123,…
- risk 0.38cvss 5.9epss 0.00
An issue was discovered in Samsung Semiconductor Mobile Processor and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos W930, Exynos Modem 5123,…
- risk 0.38cvss 5.9epss 0.00
Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore.
- risk 0.38cvss 5.9epss 0.00
Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.
- risk 0.38cvss 5.9epss 0.00
Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.
- risk 0.38cvss 5.9epss 0.00
Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.38cvss 5.9epss 0.00
Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.
- risk 0.38cvss 5.9epss 0.00
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not properly…
- risk 0.38cvss 5.9epss 0.00
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos Modem 5123, and Exynos Modem 5300. The baseband software does not properly…
- risk 0.38cvss 5.9epss 0.00
Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data.
- risk 0.38cvss 5.9epss 0.00
Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration.
- risk 0.38cvss 5.9epss 0.00
Out-of-bounds write vulnerability while decoding hcr of libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.
- risk 0.38cvss 5.9epss 0.00
Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.38cvss 5.9epss 0.00
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.
- risk 0.38cvss 5.9epss 0.00
An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
- risk 0.38cvss 5.9epss 0.00
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.
- risk 0.38cvss 5.9epss 0.01
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos Mobile Processor, Automotive Processor, and Modem - Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380,…
- risk 0.38cvss 5.9epss 0.00
Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.
- risk 0.38cvss 5.9epss 0.00
Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.
- risk 0.38cvss 5.9epss 0.00
Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
- risk 0.38cvss 5.9epss 0.00
Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.
- risk 0.38cvss 5.9epss 0.00
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
- risk 0.38cvss 5.9epss 0.00
Insertion of Sensitive Information into Log in PushRegIdUpdateClient of SReminder prior to 8.2.01.13 allows attacker to access device IMEI.
- risk 0.38cvss 5.9epss 0.00
Improper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected Bluetooth device.
- risk 0.38cvss 5.9epss 0.00
Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege.
- risk 0.38cvss 5.9epss 0.00
Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth device.
- risk 0.38cvss 5.9epss 0.00
Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.
- risk 0.38cvss 5.9epss 0.00
Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.
- risk 0.38cvss 5.9epss 0.00
Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.
- risk 0.38cvss 5.9epss 0.00
Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI privilege.
- risk 0.38cvss 5.9epss 0.00
SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP information.
- risk 0.38cvss 5.9epss 0.00
Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth device.
- risk 0.38cvss 5.9epss 0.00
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.
- risk 0.38cvss 5.9epss 0.00
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.
- risk 0.38cvss 5.9epss 0.00
Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.
Page 24 of 47