Vulnerabilities > Samsung > Health

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2023-42539 Unspecified vulnerability in Samsung Health
PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.
local
low complexity
samsung
5.5
2023-10-04 CVE-2023-30734 Unspecified vulnerability in Samsung Health
Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.
local
low complexity
samsung
5.5
2023-10-04 CVE-2023-30737 Unspecified vulnerability in Samsung Health
Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.
local
low complexity
samsung
5.5
2023-09-06 CVE-2023-30723 Unspecified vulnerability in Samsung Health 6.16/6.17/6.19.1.0001
Improper input validation vulnerability in Samsung Health prior to version 6.24.2.011 allows attackers to write arbitrary file with Samsung Health privilege.
network
low complexity
samsung
critical
9.8
2022-01-10 CVE-2022-22283 Insufficient Session Expiration vulnerability in Samsung Health 6.16/6.17/6.19.1.0001
Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.
local
low complexity
samsung CWE-613
2.1
2021-11-05 CVE-2021-25506 Incorrect Authorization vulnerability in Samsung Health
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
local
low complexity
samsung CWE-863
2.1
2021-06-11 CVE-2021-25401 Unspecified vulnerability in Samsung Health
Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.
local
low complexity
samsung
4.6
2021-06-11 CVE-2021-25425 Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Health 6.16
Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exported component.
network
low complexity
samsung CWE-754
5.0