Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2021-06-11 CVE-2021-25398 Unspecified vulnerability in Samsung Bixby Voice 3.0.52.14
Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access contacts.
local
low complexity
samsung
3.3
2021-06-11 CVE-2021-25402 Insecure Storage of Sensitive Information vulnerability in Samsung Notes 2.0.02.31/4.2.00.22
Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information.
local
low complexity
samsung CWE-922
3.3
2021-06-11 CVE-2021-25403 Unspecified vulnerability in Samsung Account 10.7.07/12.2.0.9
Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.
local
low complexity
samsung
3.3
2021-06-11 CVE-2021-25404 Insecure Storage of Sensitive Information vulnerability in Samsung Smartthings Firmware
Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log.
local
low complexity
samsung CWE-922
3.3
2021-06-11 CVE-2021-25409 Missing Authorization vulnerability in Google Android 10.0
Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.
low complexity
google CWE-862
2.4
2021-06-10 CVE-2021-31839 Unspecified vulnerability in Mcafee Agent
Improper privilege management vulnerability in McAfee Agent for Windows prior to 5.7.3 allows a local user to modify event information in the MA event folder.
local
low complexity
mcafee
3.3
2021-06-10 CVE-2021-33031 Missing Authorization vulnerability in Labcup
In LabCup before <v2_next_18022, it is possible to use the save API to perform unauthorized actions for users without access to user management in order to, after successful exploitation, gain access to a victim's account.
network
high complexity
labcup CWE-862
3.1
2021-06-10 CVE-2021-3588 Out-of-bounds Read vulnerability in Bluez
The cli_feat_read_cb() function in src/gatt-database.c does not perform bounds checks on the 'offset' variable before using it as an index into an array for reading.
local
low complexity
bluez CWE-125
3.3
2021-06-09 CVE-2020-24512 Information Exposure Through Discrepancy vulnerability in multiple products
Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel debian netapp CWE-203
3.3
2021-06-08 CVE-2021-22215 Unspecified vulnerability in Gitlab
An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak information about the members' on-call rotations in other projects
network
low complexity
gitlab
2.7