Vulnerabilities > Samsung

DATE CVE VULNERABILITY TITLE RISK
2023-03-16 CVE-2023-21455 Unspecified vulnerability in Samsung Exynos Firmware
Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.
network
low complexity
samsung
critical
9.1
2023-03-16 CVE-2023-21456 Path Traversal vulnerability in Samsung Android 11.0/12.0/13.0
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
local
low complexity
samsung CWE-22
5.5
2023-03-16 CVE-2023-21457 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.
low complexity
samsung
8.1
2023-03-16 CVE-2023-21458 Improper Privilege Management vulnerability in Samsung Android 11.0/12.0/13.0
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
local
low complexity
samsung CWE-269
3.3
2023-03-16 CVE-2023-21459 Use After Free vulnerability in Samsung Android 11.0/12.0/13.0
Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.
network
low complexity
samsung CWE-416
critical
9.8
2023-03-16 CVE-2023-21460 Improper Authentication vulnerability in Samsung Android 11.0/12.0/13.0
Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
local
low complexity
samsung CWE-287
4.4
2023-03-16 CVE-2023-21461 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
local
low complexity
samsung
5.5
2023-03-16 CVE-2023-21462 Unspecified vulnerability in Samsung Quick Share
The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.
local
low complexity
samsung
3.3
2023-03-16 CVE-2023-21463 Unspecified vulnerability in Samsung Myfiles
Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions.
local
low complexity
samsung
3.3
2023-03-16 CVE-2023-21464 Unspecified vulnerability in Samsung Calendar 12.3.05.10000
Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper status.
local
low complexity
samsung
3.3