Vulnerabilities > Samsung > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-04 CVE-2023-21485 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
low complexity
samsung
4.6
2023-05-04 CVE-2023-21486 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
low complexity
samsung
4.6
2023-05-04 CVE-2023-21489 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0/13.0
Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.
low complexity
samsung CWE-787
6.8
2023-05-04 CVE-2023-21492 Information Exposure Through Log Files vulnerability in Samsung Android 11.0/12.0/13.0
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
local
low complexity
samsung CWE-532
4.4
2023-05-04 CVE-2023-21493 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.
local
low complexity
samsung
5.5
2023-05-04 CVE-2023-21495 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
local
low complexity
samsung
5.5
2023-05-04 CVE-2023-21496 Unspecified vulnerability in Samsung Android 11.0/12.0/13.0
Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.
local
low complexity
samsung
5.5
2023-05-04 CVE-2023-21500 Double Free vulnerability in Samsung Android 13.0
Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
local
low complexity
samsung CWE-415
5.5
2023-05-04 CVE-2023-21507 Out-of-bounds Read vulnerability in Samsung Blockchain Keystore
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
local
low complexity
samsung CWE-125
5.5
2023-05-04 CVE-2023-21510 Out-of-bounds Read vulnerability in Samsung Blockchain Keystore
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
local
low complexity
samsung CWE-125
5.5