Vulnerabilities > Samsung > High

DATE CVE VULNERABILITY TITLE RISK
2017-06-21 CVE-2017-3218 Insufficient Verification of Data Authenticity vulnerability in Samsung Magician 5.0
Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic.
low complexity
samsung CWE-345
8.8
2017-06-07 CVE-2015-7888 Path Traversal vulnerability in Samsung Galaxy S6 Edge Firmware G925Vvru1Aoe2
Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a ..
network
low complexity
samsung CWE-22
7.5
2017-04-19 CVE-2017-7978 Information Exposure vulnerability in Samsung Mobile
Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot.
network
low complexity
samsung CWE-200
7.5
2017-04-11 CVE-2015-7893 Improper Input Validation vulnerability in Samsung Galaxy S6
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.
network
low complexity
samsung CWE-20
8.8
2017-03-27 CVE-2015-0864 Permissions, Privileges, and Access Controls vulnerability in Samsung Galaxy APP and Samsung Account APP
Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
low complexity
samsung CWE-264
8.0
2017-03-27 CVE-2015-0863 Permissions, Privileges, and Access Controls vulnerability in Samsung Galaxy APP and Samsung Account APP
GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
low complexity
samsung CWE-264
8.0
2017-02-27 CVE-2017-5927 Information Exposure vulnerability in multiple products
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors.
network
low complexity
intel amd samsung nvidia allwinner CWE-200
7.5
2017-02-27 CVE-2017-5926 Information Exposure vulnerability in multiple products
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors.
network
low complexity
intel amd samsung nvidia allwinner CWE-200
7.5
2017-02-27 CVE-2017-5925 Information Exposure vulnerability in multiple products
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors.
network
low complexity
intel amd samsung nvidia allwinner CWE-200
7.5
2017-02-13 CVE-2016-4547 Improper Input Validation vulnerability in Samsung Mobile
Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.
network
low complexity
samsung CWE-20
7.5