Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-25430 | Med | 0.28 | 4.3 | 0.00 | Jul 8, 2021 | Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application. | ||
| CVE-2021-25429 | Med | 0.28 | 4.3 | 0.00 | Jul 8, 2021 | Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application. | ||
| CVE-2021-25378 | Med | 0.28 | 4.3 | 0.01 | Apr 9, 2021 | Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service. | ||
| CVE-2017-18667 | Med | 0.28 | 4.3 | 0.00 | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Attackers can prevent users from learning that SMS storage space has been exhausted. The Samsung ID is SVE-2017-8702 (June 2017). | ||
| CVE-2017-18653 | Med | 0.28 | 4.3 | 0.00 | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. The Email application allows attackers to send emails on behalf of any user via a broadcasted intent. The Samsung ID is SVE-2017-9357 (September 2017). | ||
| CVE-2016-11050 | Med | 0.28 | 4.3 | 0.00 | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attacker can rewrite the IMEI by flashing crafted firmware. The Samsung ID is SVE-2016-5562 (March 2016). | ||
| CVE-2019-6744 | Med | 0.28 | 4.3 | 0.00 | Feb 10, 2020 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this… | ||
| CVE-2018-16268 | Med | 0.28 | 4.3 | 0.01 | Jan 22, 2020 | The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This affects Tizen before 5.0 M1,… | ||
| CVE-2013-4764 | Med | 0.28 | 4.3 | 0.00 | Dec 27, 2019 | Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission. | ||
| CVE-2018-14853 | Med | 0.28 | 4.3 | 0.01 | Dec 17, 2018 | A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device to… | ||
| CVE-2026-33957 | Med | 0.27 | 4.2 | 0.00 | Sep 14, 2026 | An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage. | ||
| CVE-2026-23791 | Med | 0.27 | 4.2 | 0.00 | Sep 14, 2026 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory… | ||
| CVE-2026-23790 | Med | 0.27 | 4.2 | 0.00 | Sep 14, 2026 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory… | ||
| CVE-2026-23788 | Med | 0.27 | 4.2 | 0.00 | Sep 14, 2026 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash. | ||
| CVE-2026-23787 | Med | 0.27 | 4.2 | 0.00 | Sep 14, 2026 | An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash. | ||
| CVE-2026-40448 | Med | 0.27 | 5.3 | 0.00 | Apr 22, 2026 | Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung Open Source ONE. Affected version is prior to commit 1.30.0. | ||
| CVE-2025-58476 | Med | 0.27 | 4.2 | 0.00 | Dec 2, 2025 | Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory. | ||
| CVE-2025-21037 | Med | 0.27 | 4.1 | 0.00 | Sep 3, 2025 | Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across multiple user profiles. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20999 | Med | 0.27 | 4.1 | 0.00 | Jul 8, 2025 | Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password. | ||
| CVE-2025-20886 | Med | 0.27 | 4.1 | 0.00 | Feb 4, 2025 | Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key. | ||
| CVE-2024-34673 | Med | 0.27 | 4.1 | 0.00 | Nov 6, 2024 | Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service. | ||
| CVE-2024-34664 | Med | 0.27 | 4.1 | 0.00 | Oct 8, 2024 | Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment. | ||
| CVE-2024-20873 | Med | 0.27 | 4.2 | 0.00 | Jun 4, 2024 | Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2024-20842 | Med | 0.27 | 4.2 | 0.00 | Apr 2, 2024 | Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2024-20833 | Med | 0.27 | 4.1 | 0.00 | Mar 5, 2024 | Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption. | ||
| CVE-2023-21462 | Med | 0.27 | 4.2 | 0.00 | Mar 16, 2023 | The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission. | ||
| CVE-2023-21457 | Med | 0.27 | 4.1 | 0.00 | Mar 16, 2023 | Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission. | ||
| CVE-2023-21432 | Med | 0.27 | 4.2 | 0.00 | Feb 9, 2023 | Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner. | ||
| CVE-2022-30740 | Med | 0.27 | 4.1 | 0.00 | Jun 7, 2022 | Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers. | ||
| CVE-2022-25820 | Med | 0.27 | 4.2 | 0.00 | Mar 10, 2022 | A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password. | ||
| CVE-2022-25816 | Med | 0.27 | 4.1 | 0.00 | Mar 10, 2022 | Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication | ||
| CVE-2022-24932 | Med | 0.27 | 4.2 | 0.00 | Mar 10, 2022 | Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard. | ||
| CVE-2022-24929 | Med | 0.27 | 4.1 | 0.00 | Mar 10, 2022 | Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication. | ||
| CVE-2022-24927 | Med | 0.27 | 4.2 | 0.00 | Feb 11, 2022 | Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission. | ||
| CVE-2021-25476 | Med | 0.27 | 4.1 | 0.00 | Oct 6, 2021 | An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE. | ||
| CVE-2019-12762 | Med | 0.27 | 4.2 | 0.00 | Jun 6, 2019 | Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch. | ||
| CVE-2018-12038 | Med | 0.27 | 4.2 | 0.01 | Nov 20, 2018 | An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key. | ||
| CVE-2015-7268 | Med | 0.27 | 4.2 | 0.00 | Nov 27, 2017 | Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or ThinkPad W541 laptops with BIOS 2.21, or in Opal or eDrive mode on Dell… | ||
| CVE-2015-7267 | Med | 0.27 | 4.2 | 0.00 | Nov 27, 2017 | Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with… | ||
| CVE-2026-23792 | Med | 0.26 | 4.0 | 0.00 | Sep 14, 2026 | An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to… | ||
| CVE-2026-40447 | Med | 0.26 | 5.1 | 0.00 | Apr 13, 2026 | Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335. | ||
| CVE-2025-58487 | Med | 0.26 | 4.0 | 0.00 | Dec 2, 2025 | Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege. | ||
| CVE-2025-58486 | Med | 0.26 | 4.0 | 0.00 | Dec 2, 2025 | Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script. | ||
| CVE-2025-58484 | Med | 0.26 | 4.0 | 0.00 | Dec 2, 2025 | Incorrect default permissions in Samsung Cloud Assistant prior to version 8.0.03.8 allows local attacker to access partial data in sandbox. | ||
| CVE-2025-21070 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory. | ||
| CVE-2025-21069 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory. | ||
| CVE-2025-21068 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory. | ||
| CVE-2025-21067 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory. | ||
| CVE-2025-21066 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory. | ||
| CVE-2025-21057 | Med | 0.26 | 4.0 | 0.00 | Oct 10, 2025 | Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes. |
- risk 0.28cvss 4.3epss 0.00
Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
- risk 0.28cvss 4.3epss 0.00
Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.
- risk 0.28cvss 4.3epss 0.01
Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.
- risk 0.28cvss 4.3epss 0.00
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Attackers can prevent users from learning that SMS storage space has been exhausted. The Samsung ID is SVE-2017-8702 (June 2017).
- risk 0.28cvss 4.3epss 0.00
An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. The Email application allows attackers to send emails on behalf of any user via a broadcasted intent. The Samsung ID is SVE-2017-9357 (September 2017).
- risk 0.28cvss 4.3epss 0.00
An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attacker can rewrite the IMEI by flashing crafted firmware. The Samsung ID is SVE-2016-5562 (March 2016).
- risk 0.28cvss 4.3epss 0.00
This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this…
- risk 0.28cvss 4.3epss 0.01
The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This affects Tizen before 5.0 M1,…
- risk 0.28cvss 4.3epss 0.00
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
- risk 0.28cvss 4.3epss 0.01
A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device to…
- risk 0.27cvss 4.2epss 0.00
An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage.
- risk 0.27cvss 4.2epss 0.00
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory…
- risk 0.27cvss 4.2epss 0.00
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory…
- risk 0.27cvss 4.2epss 0.00
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.
- risk 0.27cvss 4.2epss 0.00
An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash.
- risk 0.27cvss 5.3epss 0.00
Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung Open Source ONE. Affected version is prior to commit 1.30.0.
- risk 0.27cvss 4.2epss 0.00
Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.
- risk 0.27cvss 4.1epss 0.00
Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across multiple user profiles. User interaction is required for triggering this vulnerability.
- risk 0.27cvss 4.1epss 0.00
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.
- risk 0.27cvss 4.1epss 0.00
Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.
- risk 0.27cvss 4.1epss 0.00
Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.
- risk 0.27cvss 4.1epss 0.00
Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment.
- risk 0.27cvss 4.2epss 0.00
Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.27cvss 4.2epss 0.00
Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.27cvss 4.1epss 0.00
Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.
- risk 0.27cvss 4.2epss 0.00
The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
- risk 0.27cvss 4.1epss 0.00
Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.
- risk 0.27cvss 4.2epss 0.00
Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.
- risk 0.27cvss 4.1epss 0.00
Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.
- risk 0.27cvss 4.2epss 0.00
A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.
- risk 0.27cvss 4.1epss 0.00
Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication
- risk 0.27cvss 4.2epss 0.00
Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.
- risk 0.27cvss 4.1epss 0.00
Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.
- risk 0.27cvss 4.2epss 0.00
Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.
- risk 0.27cvss 4.1epss 0.00
An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.
- risk 0.27cvss 4.2epss 0.00
Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.
- risk 0.27cvss 4.2epss 0.01
An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key.
- risk 0.27cvss 4.2epss 0.00
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or ThinkPad W541 laptops with BIOS 2.21, or in Opal or eDrive mode on Dell…
- risk 0.27cvss 4.2epss 0.00
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with…
- risk 0.26cvss 4.0epss 0.00
An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to…
- risk 0.26cvss 5.1epss 0.00
Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.
- risk 0.26cvss 4.0epss 0.00
Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.
- risk 0.26cvss 4.0epss 0.00
Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.
- risk 0.26cvss 4.0epss 0.00
Incorrect default permissions in Samsung Cloud Assistant prior to version 8.0.03.8 allows local attacker to access partial data in sandbox.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.
Page 37 of 47