Vulnerabilities > Samsung

DATE CVE VULNERABILITY TITLE RISK
2023-02-09 CVE-2023-21447 Exposure of Resource to Wrong Sphere vulnerability in Samsung Cloud 4.7.0.3/5.1.0.8/5.2.00.7
Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent.
local
low complexity
samsung CWE-668
3.3
2023-02-09 CVE-2023-21448 Path Traversal vulnerability in Samsung Cloud 4.7.0.3/5.1.0.8/5.2.00.7
Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file.
local
low complexity
samsung CWE-22
3.3
2023-02-09 CVE-2023-21450 Missing Authorization vulnerability in Samsung ONE Hand Operation +
Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner's widget without authorization via gesture setting.
low complexity
samsung CWE-862
2.1
2023-02-09 CVE-2023-21451 Out-of-bounds Write vulnerability in Samsung Android 12.0
A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.
local
low complexity
samsung CWE-787
7.8
2022-12-13 CVE-2022-44636 Unspecified vulnerability in Samsung products
The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button.
low complexity
samsung
4.6
2022-12-08 CVE-2022-39901 Improper Authentication vulnerability in Samsung Exynos Firmware
Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.
low complexity
samsung CWE-287
6.5
2022-12-08 CVE-2022-39902 Unspecified vulnerability in Samsung Exynos Firmware
Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.
network
low complexity
samsung
7.5
2022-12-08 CVE-2022-39909 Insufficient Verification of Data Authenticity vulnerability in Samsung Gear Iconx PC Manager 2.1.220405.51
Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.
local
low complexity
samsung CWE-345
5.5
2022-12-08 CVE-2022-39910 Unspecified vulnerability in Samsung Pass 4.0.05.1
Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view.
high complexity
samsung
4.2
2022-12-08 CVE-2022-39911 Unspecified vulnerability in Samsung Pass 4.0.05.1
Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass.
low complexity
samsung
6.8