Vulnerabilities > Samsung

DATE CVE VULNERABILITY TITLE RISK
2021-11-05 CVE-2021-25507 Unspecified vulnerability in Samsung Flow
Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.
low complexity
samsung
5.7
2021-11-05 CVE-2021-25508 Improper Privilege Management vulnerability in Samsung Smartthings
Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitation.
network
low complexity
samsung CWE-269
critical
9.8
2021-11-05 CVE-2021-25509 Improper Input Validation vulnerability in Samsung Flow
A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows known folders.
local
low complexity
samsung CWE-20
7.1
2021-10-06 CVE-2021-25487 Out-of-bounds Read vulnerability in Samsung Android
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
local
low complexity
samsung CWE-125
7.8
2021-10-06 CVE-2021-25489 Use of Externally-Controlled Format String vulnerability in Samsung Android
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
local
low complexity
samsung CWE-134
5.5
2021-10-06 CVE-2021-25492 Out-of-bounds Read vulnerability in Samsung Notes 2.0.02.31/4.2.00.22/4.2.04.27
Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.
local
low complexity
samsung CWE-125
7.1
2021-10-06 CVE-2021-25493 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Samsung Notes 2.0.02.31/4.2.00.22/4.2.04.27
Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read
local
low complexity
samsung CWE-119
7.1
2021-10-06 CVE-2021-25494 Classic Buffer Overflow vulnerability in Samsung Notes 2.0.02.31/4.2.00.22/4.2.04.27
A possible buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.
local
low complexity
samsung CWE-120
7.8
2021-10-06 CVE-2021-25495 Out-of-bounds Write vulnerability in Samsung Notes 2.0.02.31/4.2.00.22/4.2.04.27
A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.
local
low complexity
samsung CWE-787
7.8
2021-10-06 CVE-2021-25496 Classic Buffer Overflow vulnerability in Samsung Notes 2.0.02.31/4.2.00.22/4.2.04.27
A possible buffer overflow vulnerability in maetd_dec_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.
local
low complexity
samsung CWE-120
7.8