Vulnerabilities > Samsung > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-01-10 CVE-2022-22289 Improper Authentication vulnerability in Samsung S Assistant
Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.
network
low complexity
samsung CWE-287
5.0
2021-12-08 CVE-2021-25520 Cross-site Scripting vulnerability in Samsung Internet
Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.
network
samsung CWE-79
4.3
2021-11-05 CVE-2021-25505 Improper Authentication vulnerability in Samsung Pass
Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.
network
samsung CWE-287
6.8
2021-10-06 CVE-2021-25494 Classic Buffer Overflow vulnerability in Samsung Notes
A possible buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.
local
low complexity
samsung CWE-120
4.6
2021-10-06 CVE-2021-25495 Out-of-bounds Write vulnerability in Samsung Notes
A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.
local
low complexity
samsung CWE-787
4.6
2021-10-06 CVE-2021-25496 Classic Buffer Overflow vulnerability in Samsung Notes
A possible buffer overflow vulnerability in maetd_dec_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.
local
low complexity
samsung CWE-120
4.6
2021-10-06 CVE-2021-25497 Classic Buffer Overflow vulnerability in Samsung Notes
A possible buffer overflow vulnerability in maetd_cpy_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.
local
low complexity
samsung CWE-120
4.6
2021-10-06 CVE-2021-25498 Classic Buffer Overflow vulnerability in Samsung Notes
A possible buffer overflow vulnerability in maetd_eco_cb_mode of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.
local
low complexity
samsung CWE-120
4.6
2021-09-09 CVE-2021-25465 Improper Input Validation vulnerability in Samsung Themes
An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack.
local
samsung CWE-20
4.4
2021-09-09 CVE-2021-25466 Improper Authentication vulnerability in Samsung Internet
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.
network
low complexity
samsung CWE-287
5.0