Vulnerabilities > Samsung > Android > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-06 CVE-2023-30668 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0/13.0
Out-of-bounds Write in BuildOemSecureSimLockResponse of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
local
low complexity
samsung CWE-787
7.8
2023-07-06 CVE-2023-30669 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0/13.0
Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
local
low complexity
samsung CWE-787
7.8
2023-07-06 CVE-2023-30670 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0/13.0
Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
local
low complexity
samsung CWE-787
7.8
2023-05-04 CVE-2023-21484 Improper Authentication vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.
local
low complexity
samsung CWE-287
7.8
2023-05-04 CVE-2023-21488 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.
local
low complexity
samsung
7.8
2023-05-04 CVE-2023-21490 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.
local
low complexity
samsung
7.1
2023-05-04 CVE-2023-21491 Unspecified vulnerability in Samsung Android 12.0/13.0
Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.
local
low complexity
samsung
7.8
2023-05-04 CVE-2023-21497 Use of Externally-Controlled Format String vulnerability in Samsung Android 13.0
Use of externally-controlled format string vulnerability in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the memory address.
local
low complexity
samsung CWE-134
7.8
2023-05-04 CVE-2023-21498 Improper Input Validation vulnerability in Samsung Android 13.0
Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.
local
low complexity
samsung CWE-20
7.8
2023-05-04 CVE-2023-21499 Out-of-bounds Write vulnerability in Samsung Android 13.0
Out-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.
local
low complexity
samsung CWE-787
7.8