Vulnerabilities > Samsung > Galaxy S4 Mini > High

DATE CVE VULNERABILITY TITLE RISK
2016-10-31 CVE-2016-7991 7PK - Errors vulnerability in Google Android
On Samsung Galaxy S4 through S7 devices, the "omacp" app ignores security information embedded in the OMACP messages resulting in remote unsolicited WAP Push SMS messages being accepted, parsed, and handled by the device, leading to unauthorized configuration changes, a subset of SVE-2016-6542.
network
low complexity
google samsung CWE-388
7.8
2016-10-31 CVE-2016-7989 7PK - Security Features vulnerability in Google Android
On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message sent remotely triggers an unhandled ArrayIndexOutOfBoundsException in Samsung's implementation of the WifiServiceImpl class within wifi-service.jar.
network
low complexity
google samsung CWE-254
7.8
2016-10-31 CVE-2016-7988 Permission Issues vulnerability in Google Android
On Samsung Galaxy S4 through S7 devices, absence of permissions on the BroadcastReceiver responsible for handling the com.[Samsung].android.intent.action.SET_WIFI intent leads to unsolicited configuration messages being handled by wifi-service.jar within the Android Framework, a subset of SVE-2016-6542.
network
low complexity
google samsung CWE-275
7.8