Vulnerabilities > Samsung > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-06-07 CVE-2022-30745 Unspecified vulnerability in Samsung Quick Share 3.5.14.18/3.5.16.20
Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share.
local
low complexity
samsung
5.5
2022-06-07 CVE-2022-30749 Improper Authentication vulnerability in Samsung Smartthings 1.7.73.22/1.7.85.12
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.
local
low complexity
samsung CWE-287
4.6
2022-05-03 CVE-2022-28792 Uncontrolled Search Path Element vulnerability in Samsung Gear Iconx PC Manager
DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code.
4.4
2022-04-11 CVE-2022-27839 Improper Authentication vulnerability in Samsung Internet
Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.
network
samsung CWE-287
4.3
2022-04-11 CVE-2022-27842 Uncontrolled Search Path Element vulnerability in Samsung Smart Switch PC
DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.
4.4
2022-04-11 CVE-2022-27843 Uncontrolled Search Path Element vulnerability in Samsung Kies 2.3.2.12074/2.3.2.120741313/2.5.0.120942711
DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.
4.4
2022-04-11 CVE-2022-28541 Uncontrolled Search Path Element vulnerability in Samsung Update
Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.
local
low complexity
samsung CWE-427
4.6
2022-04-11 CVE-2022-28544 Path Traversal vulnerability in Samsung Galaxy Store 4.5.32.4
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.
network
low complexity
samsung CWE-22
5.0
2022-04-11 CVE-2022-28779 Uncontrolled Search Path Element vulnerability in Samsung Android USB Driver Windows Installer
Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code.
local
low complexity
samsung CWE-427
4.6
2022-04-05 CVE-2022-25154 Uncontrolled Search Path Element vulnerability in Samsung T5 Firmware
A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escalate privileges.
4.4