Vulnerabilities > Samsung > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-04 CVE-2023-21492 Information Exposure Through Log Files vulnerability in Samsung Android 11.0/12.0/13.0
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
local
low complexity
samsung CWE-532
4.4
2023-05-04 CVE-2023-21493 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.
local
low complexity
samsung
5.5
2023-05-04 CVE-2023-21495 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
local
low complexity
samsung
5.5
2023-05-04 CVE-2023-21496 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.
local
low complexity
samsung
5.5
2023-05-04 CVE-2023-21500 Double Free vulnerability in Samsung Android 13.0
Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
local
low complexity
samsung CWE-415
5.5
2023-03-16 CVE-2023-21449 Unspecified vulnerability in Samsung Android 11.0/12.0
Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.
local
low complexity
samsung
5.5
2023-03-16 CVE-2023-21453 Improper Input Validation vulnerability in Samsung Android 13.0
Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
local
low complexity
samsung CWE-20
5.5
2023-03-16 CVE-2023-21456 Path Traversal vulnerability in Samsung Android 11.0/12.0/13.0
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
local
low complexity
samsung CWE-22
5.5
2023-03-16 CVE-2023-21460 Improper Authentication vulnerability in Samsung Android 11.0/12.0/13.0
Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
local
low complexity
samsung CWE-287
4.4
2023-03-16 CVE-2023-21461 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
local
low complexity
samsung
5.5