Vulnerabilities > Samsung > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-07-06 CVE-2023-30678 Path Traversal vulnerability in Samsung Calendar
Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.
local
low complexity
samsung CWE-22
5.5
2023-06-28 CVE-2023-21513 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
low complexity
samsung
6.8
2023-05-04 CVE-2023-21485 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
low complexity
samsung
4.6
2023-05-04 CVE-2023-21486 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
low complexity
samsung
4.6
2023-05-04 CVE-2023-21489 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0/13.0
Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.
low complexity
samsung CWE-787
6.8
2023-05-04 CVE-2023-21492 Information Exposure Through Log Files vulnerability in Samsung Android 11.0/12.0/13.0
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
local
low complexity
samsung CWE-532
4.4
2023-05-04 CVE-2023-21493 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.
local
low complexity
samsung
5.5
2023-05-04 CVE-2023-21495 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
local
low complexity
samsung
5.5
2023-05-04 CVE-2023-21496 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.
local
low complexity
samsung
5.5
2023-05-04 CVE-2023-21500 Double Free vulnerability in Samsung Android 13.0
Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
local
low complexity
samsung CWE-415
5.5