Vulnerabilities > Samsung > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-02-20 CVE-2017-10963 Injection vulnerability in Samsung products
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain point in the update sequence.
network
samsung CWE-74
4.3
2018-01-18 CVE-2017-17860 Improper Input Validation vulnerability in Google Android
In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key.
5.7
2017-12-28 CVE-2015-7889 Permission Issues vulnerability in Google Android
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge of the local email address to obtain sensitive information via a crafted application that sends a crafted intent.
4.3
2017-12-27 CVE-2017-17859 Cross-site Scripting vulnerability in Samsung Internet Browser 6.2.01.12
Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part of an MHTML file.
network
samsung CWE-79
4.3
2017-12-21 CVE-2017-17692 Information Exposure vulnerability in Samsung Internet Browser 5.4.02.3
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
network
low complexity
samsung CWE-200
5.0
2017-11-06 CVE-2017-16524 Unrestricted Upload of File with Dangerous Type vulnerability in Hanwhasecurity web Viewer 1.0.0.193
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php extension, which is then accessed via a direct request to the file in the upload/ directory.
network
low complexity
hanwhasecurity samsung CWE-434
6.5
2017-10-16 CVE-2017-15361 Unspecified vulnerability in Infineon RSA Library and Trusted Platform Firmware
The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 0000000000008521 - 133.33, mishandles RSA key generation, which makes it easier for attackers to defeat various cryptographic protection mechanisms via targeted attacks, aka ROCA.
4.3
2017-09-26 CVE-2014-0997 Data Processing Errors vulnerability in Google Android 4.1.2/4.2.2/4.4.4
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used in the Samsung SM-T310, Android 4.1.2 as used in the Motorola RAZR HD, and potentially other unspecified Android releases before 5.0.1 and 5.0.2 does not properly handle exceptions, which allows remote attackers to cause a denial of service (reboot) via a crafted 802.11 probe response frame.
network
low complexity
google lg samsung motorola CWE-19
5.0
2017-08-24 CVE-2015-7896 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Samsung Mobile
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.
network
samsung CWE-119
4.3
2017-08-24 CVE-2015-1800 Information Exposure vulnerability in Samsung Galaxy S4 Firmware I9500Xxuemk8
The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive information.
network
low complexity
samsung CWE-200
5.0