Vulnerabilities > Samsung > High

DATE CVE VULNERABILITY TITLE RISK
2017-02-01 CVE-2016-4038 Improper Input Validation vulnerability in Samsung Mobile 4.4/5.0/5.1
Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/msm/camera_v2/sensor/msm_sensor.c in Samsung devices with Android KK(4.4) or L and an APQ8084, MSM8974, or MSM8974pro chipset allows local users to have unspecified impact via the gpio_config.gpio_name value.
local
low complexity
samsung CWE-20
7.8
2017-01-18 CVE-2016-9279 Use After Free vulnerability in Samsung Exynos Fimg2D Driver
Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors.
network
low complexity
samsung CWE-416
7.5
2017-01-18 CVE-2016-6527 Permissions, Privileges, and Access Controls vulnerability in Samsung Mobile 5.0/5.1/6.0
The SmartCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed serializable object.
local
low complexity
samsung CWE-264
7.8
2017-01-18 CVE-2016-6526 Permissions, Privileges, and Access Controls vulnerability in Samsung Mobile 5.0/5.1/6.0
The SpamCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed serializable object.
local
low complexity
samsung CWE-264
7.8
2017-01-12 CVE-2017-5351 Resource Exhaustion vulnerability in Samsung Mobile
Samsung Note devices with KK(4.4), L(5.0/5.1), and M(6.0) software allow attackers to crash the system by creating an arbitrarily large number of active VR service threads.
network
low complexity
samsung CWE-400
7.5
2017-01-12 CVE-2017-5350 Unspecified vulnerability in Samsung Mobile
Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allow attackers to crash systemUI by leveraging incomplete exception handling.
network
low complexity
samsung
7.5
2016-11-11 CVE-2016-9277 Integer Overflow or Wraparound vulnerability in Samsung Mobile 4.4/5.0/5.1
Integer overflow in SystemUI in KK(4.4) and L(5.0/5.1) on Samsung Note devices allows attackers to cause a denial of service (UI restart) via vectors involving APIs and an activity that computes an out-of-bounds array index, aka SVE-2016-6906.
network
low complexity
samsung CWE-190
7.5
2016-11-03 CVE-2016-7160 NULL Pointer Dereference vulnerability in Samsung Mobile 6.0
A vulnerability on Samsung Mobile M(6.0) devices exists because external access to SystemUI activities is not properly restricted, leading to a SystemUI crash and device restart, aka SVE-2016-6248.
network
low complexity
samsung CWE-476
7.5
2016-03-26 CVE-2016-1350 Resource Management Errors vulnerability in multiple products
Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.
network
low complexity
cisco samsung sun zyxel lenovo zzinc CWE-399
7.5
2016-03-26 CVE-2016-1349 Resource Management Errors vulnerability in multiple products
The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.
network
low complexity
cisco samsung sun intel zyxel netgear zzinc CWE-399
7.5