Vulnerabilities > Samsung > High

DATE CVE VULNERABILITY TITLE RISK
2017-04-11 CVE-2015-7893 Improper Input Validation vulnerability in Samsung Galaxy S6
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.
network
low complexity
samsung CWE-20
8.8
2017-03-27 CVE-2015-0864 Permissions, Privileges, and Access Controls vulnerability in Samsung Galaxy APP and Samsung Account APP
Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
low complexity
samsung CWE-264
8.0
2017-03-27 CVE-2015-0863 Permissions, Privileges, and Access Controls vulnerability in Samsung Galaxy APP and Samsung Account APP
GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
low complexity
samsung CWE-264
8.0
2017-02-27 CVE-2017-5927 Information Exposure vulnerability in multiple products
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors.
network
low complexity
intel amd samsung nvidia allwinner CWE-200
7.5
2017-02-27 CVE-2017-5926 Information Exposure vulnerability in multiple products
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors.
network
low complexity
intel amd samsung nvidia allwinner CWE-200
7.5
2017-02-27 CVE-2017-5925 Information Exposure vulnerability in multiple products
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors.
network
low complexity
intel amd samsung nvidia allwinner CWE-200
7.5
2017-02-13 CVE-2016-4547 Improper Input Validation vulnerability in Samsung Mobile
Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.
network
low complexity
samsung CWE-20
7.5
2017-02-01 CVE-2016-4038 Improper Input Validation vulnerability in Samsung Mobile 4.4/5.0/5.1
Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/msm/camera_v2/sensor/msm_sensor.c in Samsung devices with Android KK(4.4) or L and an APQ8084, MSM8974, or MSM8974pro chipset allows local users to have unspecified impact via the gpio_config.gpio_name value.
local
low complexity
samsung CWE-20
7.8
2017-01-18 CVE-2016-9279 Use After Free vulnerability in Samsung Exynos Fimg2D Driver
Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors.
network
low complexity
samsung CWE-416
7.5
2017-01-18 CVE-2016-6527 Permissions, Privileges, and Access Controls vulnerability in Samsung Mobile 5.0/5.1/6.0
The SmartCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed serializable object.
local
low complexity
samsung CWE-264
7.8