VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2022-39877MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.

  • CVE-2022-39874MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

  • CVE-2022-39871MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.

  • CVE-2022-39870MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.

  • CVE-2022-39869MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.

  • CVE-2022-39868MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.

  • CVE-2022-39867MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via SHOW_PERSISTENT_BANNER broadcast.

  • CVE-2022-39866MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.

  • CVE-2022-39865MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.

  • CVE-2022-39859MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit intent hijacking vulnerability in UPHelper library prior to version 3.0.12 allows attackers to access sensitive information via implicit intent.

  • CVE-2022-39856MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call information.

  • CVE-2022-39851MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.

  • CVE-2022-39848MedOct 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Exposure of sensitive information in AT_Distributor prior to SMR Oct-2022 Release 1 allows local attacker to access SerialNo via log.

  • CVE-2022-36866MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.

  • CVE-2022-36865MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to access device information.

  • CVE-2022-36864MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.

  • CVE-2022-36856MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined permission.

  • CVE-2022-36854MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.

  • CVE-2022-36850MedSep 9, 2022
    risk 0.26cvss 4.0epss 0.00

    Path traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary file with phone uid.

  • CVE-2022-36838MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information.

  • CVE-2022-36832MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege.

  • CVE-2022-33728MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via Settings.Gloabal.

  • CVE-2022-33725MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to access content providers with system privilege.

  • CVE-2022-33722MedAug 5, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.

  • CVE-2022-33696MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

  • CVE-2022-33694MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wifi information via unprotected intent broadcasting.

  • CVE-2022-33692MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

  • CVE-2022-33690MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper input validation in Contacts Storage prior to SMR Jul-2022 Release 1 allows attacker to access arbitrary file.

  • CVE-2022-33685MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.

  • CVE-2022-30758MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with privilege of Finder.

  • CVE-2022-30757MedJul 12, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.

  • CVE-2022-30748MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity.

  • CVE-2022-30745MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share.

  • CVE-2022-30739MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.

  • CVE-2022-30737MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.01

    Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.

  • CVE-2022-30734MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.01

    Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.

  • CVE-2022-30733MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.01

    Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.

  • CVE-2022-30725MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

  • CVE-2022-30724MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionCompleted function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

  • CVE-2022-30723MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

  • CVE-2022-30717MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.

  • CVE-2022-30716MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.

  • CVE-2022-30715MedJun 7, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.

  • CVE-2022-28790MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

  • CVE-2022-28788MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

  • CVE-2022-28787MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

  • CVE-2022-28786MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

  • CVE-2022-28785MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

  • CVE-2022-28784MedMay 3, 2022
    risk 0.26cvss 4.0epss 0.00

    Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.

  • CVE-2022-28543MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission.

Page 40 of 47