Vulnerabilities > Samsung

DATE CVE VULNERABILITY TITLE RISK
2023-07-06 CVE-2023-30678 Path Traversal vulnerability in Samsung Calendar
Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.
local
low complexity
samsung CWE-22
5.5
2023-06-28 CVE-2023-21512 Incorrect Default Permissions vulnerability in Samsung Android 11.0/12.0/13.0
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.
local
low complexity
samsung CWE-276
3.3
2023-06-28 CVE-2023-21513 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
low complexity
samsung
6.8
2023-06-28 CVE-2023-21517 Out-of-bounds Write vulnerability in Samsung Exynos
Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execute arbitrary code.
network
low complexity
samsung CWE-787
critical
9.8
2023-06-28 CVE-2023-21518 Unspecified vulnerability in Samsung Searchwidget 2.3.00.6
Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.
local
low complexity
samsung
7.8
2023-06-07 CVE-2023-31114 Incorrect Resource Transfer Between Spheres vulnerability in Samsung Exynos 5123 Firmware and Exynos 5300 Firmware
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300.
network
low complexity
samsung CWE-669
critical
9.1
2023-06-07 CVE-2023-31115 Incorrect Resource Transfer Between Spheres vulnerability in Samsung Exynos 5123 Firmware and Exynos 5300 Firmware
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300.
network
low complexity
samsung CWE-669
7.5
2023-06-07 CVE-2023-31116 Incorrect Default Permissions vulnerability in Samsung Exynos 5123 Firmware and Exynos 5300 Firmware
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300.
network
low complexity
samsung CWE-276
critical
9.8
2023-05-26 CVE-2023-21514 Improper Input Validation vulnerability in Samsung Galaxy Store 4.5.32.4/4.5.36.4/4.5.41.8
Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
network
low complexity
samsung CWE-20
8.8
2023-05-26 CVE-2023-21515 Unspecified vulnerability in Samsung Galaxy Store 4.5.32.4/4.5.36.4/4.5.41.8
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
network
low complexity
samsung
8.8