Vulnerabilities > Samsung > Android > 10.0

DATE CVE VULNERABILITY TITLE RISK
2023-02-09 CVE-2023-21420 Use of Externally-Controlled Format String vulnerability in Samsung Android 10.0/11.0
Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.
local
low complexity
samsung CWE-134
7.8
2023-02-09 CVE-2023-21421 Improper Privilege Management vulnerability in Samsung Android 10.0/11.0
Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.
local
low complexity
samsung CWE-269
7.8
2023-02-09 CVE-2023-21425 Improper Authentication vulnerability in Samsung Android 10.0/11.0
Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.
local
low complexity
samsung CWE-287
5.5
2023-02-09 CVE-2023-21426 Use of Hard-coded Credentials vulnerability in Samsung Android 10.0
Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.
local
low complexity
samsung CWE-798
5.5
2023-02-09 CVE-2023-21429 Unspecified vulnerability in Samsung Android 10.0/11.0
Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
local
low complexity
samsung
3.3
2023-02-09 CVE-2023-21430 Out-of-bounds Read vulnerability in Samsung Android 10.0/11.0
An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.
local
low complexity
samsung CWE-125
7.8
2023-02-09 CVE-2023-21436 Unspecified vulnerability in Samsung Android 10.0/11.0
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
local
low complexity
samsung
3.3
2023-02-09 CVE-2023-21437 Improper Authentication vulnerability in Samsung Android 10.0/11.0
Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.
local
low complexity
samsung CWE-287
5.5
2023-02-09 CVE-2023-21441 Insufficient Verification of Data Authenticity vulnerability in Samsung Android 10.0/11.0
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.
local
low complexity
samsung CWE-345
5.5