Vulnerabilities > Samsung > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-07 CVE-2023-42536 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0
An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
local
low complexity
samsung CWE-787
7.8
2023-11-07 CVE-2023-42537 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0
An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
local
low complexity
samsung CWE-787
7.8
2023-11-07 CVE-2023-42538 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0
An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
local
low complexity
samsung CWE-787
7.8
2023-11-07 CVE-2023-42543 Unspecified vulnerability in Samsung Bixby Voice 3.0.52.14/3.1.12
Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege.
network
low complexity
samsung
7.5
2023-11-07 CVE-2023-42545 Unspecified vulnerability in Samsung Phone 12.7.20.12
Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12, and 14.7.38 in Android 13 allows attackers to access location data.
network
low complexity
samsung
7.5
2023-10-04 CVE-2023-30690 Improper Input Validation vulnerability in Samsung Android 11.0/12.0
Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
local
low complexity
samsung CWE-20
7.8
2023-10-04 CVE-2023-30692 Unspecified vulnerability in Samsung Android 11.0/12.0
Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
local
low complexity
samsung
7.8
2023-10-04 CVE-2023-30727 Unspecified vulnerability in Samsung Android 11.0/12.0
Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi and connect arbitrary Wi-Fi without User Interaction.
network
low complexity
samsung
7.5
2023-10-04 CVE-2023-30733 Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0
Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attackers to perform code execution.
local
low complexity
samsung CWE-787
7.8
2023-10-04 CVE-2023-30738 Unspecified vulnerability in Samsung products
An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attacker to execute SMM memory corruption.
local
low complexity
samsung
7.8