Vulnerabilities > Samsung > Android > 11.0

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-42570 Unspecified vulnerability in Samsung Android 11.0/14.0
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.
local
low complexity
samsung
3.3
2023-11-07 CVE-2023-30739 Unspecified vulnerability in Samsung Android 11.0/12.0
Arbitrary File Descriptor Write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.
local
low complexity
samsung
7.8
2023-11-07 CVE-2023-42527 Improper Input Validation vulnerability in Samsung Android 11.0/12.0
Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.
local
low complexity
samsung CWE-20
5.5
2023-11-07 CVE-2023-42528 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0
Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.
local
low complexity
samsung CWE-787
7.8
2023-11-07 CVE-2023-42529 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0
Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.
local
low complexity
samsung CWE-787
7.8
2023-11-07 CVE-2023-42530 Unspecified vulnerability in Samsung Android 11.0/12.0
Improper access control vulnerability in SecSettings prior to SMR Nov-2023 Release 1 allows attackers to enable Wi-Fi and Wi-Fi Direct without User Interaction.
network
low complexity
samsung
7.5
2023-11-07 CVE-2023-42531 Improper Authentication vulnerability in Samsung Android 11.0/12.0
Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.
local
low complexity
samsung CWE-287
7.1
2023-11-07 CVE-2023-42532 Improper Certificate Validation vulnerability in Samsung Android 11.0/12.0
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.
network
low complexity
samsung CWE-295
7.5
2023-11-07 CVE-2023-42536 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0
An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
local
low complexity
samsung CWE-787
7.8
2023-11-07 CVE-2023-42537 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0
An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
local
low complexity
samsung CWE-787
7.8