Vulnerabilities > Samsung
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-02-09 | CVE-2023-21447 | Exposure of Resource to Wrong Sphere vulnerability in Samsung Cloud 4.7.0.3/5.1.0.8/5.2.00.7 Improper access control vulnerabilities in Samsung Cloud prior to version 5.3.0.32 allows local attackers to access information with Samsung Cloud's privilege via implicit intent. | 3.3 |
2023-02-09 | CVE-2023-21448 | Path Traversal vulnerability in Samsung Cloud 4.7.0.3/5.1.0.8/5.2.00.7 Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file. | 3.3 |
2023-02-09 | CVE-2023-21450 | Missing Authorization vulnerability in Samsung ONE Hand Operation + Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner's widget without authorization via gesture setting. | 2.1 |
2023-02-09 | CVE-2023-21451 | Out-of-bounds Write vulnerability in Samsung Android 12.0 A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions. | 7.8 |
2022-12-13 | CVE-2022-44636 | Unspecified vulnerability in Samsung products The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. low complexity samsung | 4.6 |
2022-12-08 | CVE-2022-39901 | Improper Authentication vulnerability in Samsung Exynos Firmware Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB. | 6.5 |
2022-12-08 | CVE-2022-39902 | Unspecified vulnerability in Samsung Exynos Firmware Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call. | 7.5 |
2022-12-08 | CVE-2022-39909 | Insufficient Verification of Data Authenticity vulnerability in Samsung Gear Iconx PC Manager 2.1.220405.51 Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link. | 5.5 |
2022-12-08 | CVE-2022-39910 | Unspecified vulnerability in Samsung Pass 4.0.05.1 Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view. high complexity samsung | 4.2 |
2022-12-08 | CVE-2022-39911 | Unspecified vulnerability in Samsung Pass 4.0.05.1 Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass. low complexity samsung | 6.8 |