Vulnerabilities > Samsung > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-05 CVE-2023-42556 Unspecified vulnerability in Samsung Android 11.0/14.0
Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.
local
low complexity
samsung
5.5
2023-12-05 CVE-2023-42557 Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0/14.0
Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.
local
low complexity
samsung CWE-787
6.7
2023-12-05 CVE-2023-42559 Improper Handling of Exceptional Conditions vulnerability in Samsung Android 11.0/14.0
Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.
low complexity
samsung CWE-755
5.2
2023-12-05 CVE-2023-42561 Out-of-bounds Write vulnerability in Samsung Android 11.0/14.0
Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.
low complexity
samsung CWE-787
6.8
2023-12-05 CVE-2023-42564 Unspecified vulnerability in Samsung Android 12.0/13.0/14.0
Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
local
low complexity
samsung
5.5
2023-12-05 CVE-2023-42565 Unspecified vulnerability in Samsung Android 13.0/14.0
Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.
local
low complexity
samsung
6.7
2023-12-05 CVE-2023-42568 Unspecified vulnerability in Samsung Android 12.0/13.0
Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
local
low complexity
samsung
4.4
2023-11-07 CVE-2023-42527 Improper Input Validation vulnerability in Samsung Android 11.0/12.0
Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.
local
low complexity
samsung CWE-20
5.5
2023-11-07 CVE-2023-42533 Unspecified vulnerability in Samsung Android 12.0/13.0
Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.
low complexity
samsung
6.8
2023-11-07 CVE-2023-42534 Files or Directories Accessible to External Parties vulnerability in Samsung Android 12.0/13.0
Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.
local
low complexity
samsung CWE-552
5.5