Vulnerabilities > Samsung

DATE CVE VULNERABILITY TITLE RISK
2022-09-09 CVE-2022-36870 Unspecified vulnerability in Samsung PAY and Samsung PAY KR
Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
local
low complexity
samsung
6.5
2022-09-09 CVE-2022-36871 Unspecified vulnerability in Samsung PAY and Samsung PAY KR
Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
local
low complexity
samsung
6.5
2022-09-09 CVE-2022-36872 Unspecified vulnerability in Samsung PAY and Samsung PAY KR
Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
local
low complexity
samsung
6.5
2022-09-09 CVE-2022-36875 Unspecified vulnerability in Samsung Galaxy Watch Plugin 2.2.05.21033151/2.2.05.220126741/2.2.05.22012751
Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.
local
low complexity
samsung
5.5
2022-09-09 CVE-2022-36876 Unspecified vulnerability in Samsung Pass 3.0.02.4/3.7.07.5/4.0.03.1
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.
low complexity
samsung
2.4
2022-08-05 CVE-2022-33733 Unspecified vulnerability in Samsung Charm
Sensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.
local
low complexity
samsung
3.3
2022-08-05 CVE-2022-33734 Unspecified vulnerability in Samsung Charm
Sensitive information exposure in onCharacteristicChanged in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.
local
low complexity
samsung
5.5
2022-08-05 CVE-2022-36829 Unspecified vulnerability in Samsung Charm Firmware
PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
local
low complexity
samsung
5.5
2022-08-05 CVE-2022-36830 Unspecified vulnerability in Samsung Charm Firmware
PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
local
low complexity
samsung
5.5
2022-08-05 CVE-2022-36831 Path Traversal vulnerability in Samsung Notes
Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.
local
low complexity
samsung CWE-22
5.5