3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-24929
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2022 CWE-926 1 PoC

Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.

CVE-2022-25816
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication

CVE-2022-32491
CPG BIOS General
4.1
MEDIUM
EPSS
0.0%
2022 CWE-119 1 PoC

Dell Client BIOS contains a Buffer Overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by manipulating an SMI to cause an arbitrary write during SMM.

CVE-2022-0414
dolibarr/dolibarr General
4.1
MEDIUM
EPSS
0.3%
2022 CWE-1284 1 PoC

Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.

CVE-2022-30740
Samsung Internet General
4.1
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.

CVE-2022-25824
BixbyTouch General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in BixbyTouch prior to version 2.2.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

CVE-2022-36865
Group Sharing General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to access device information.

CVE-2022-30716
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-280 1 PoC

Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.

CVE-2022-28784
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-22 1 PoC

Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.

CVE-2022-1222
gpac/gpac General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-835 1 PoC

Inf loop in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-27824
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-125 1 PoC

Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file

CVE-2022-33728
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via Settings.Gloabal.

CVE-2022-33685
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-561 1 PoC

Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.

CVE-2022-33696
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-213 1 PoC

Exposure of Sensitive Information in Telephony service prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

CVE-2022-23997
Samsung Wearable Devices General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Unprotected component vulnerability in StTheaterModeDurationAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to disable theater mode without a proper permission.

CVE-2022-29945
Software Genérico General
4.0
MEDIUM
EPSS
0.2%
2022 1 PoC

DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.

CVE-2022-36854
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.

CVE-2022-39851
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.

CVE-2022-23995
Samsung Wearable Devices General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

CVE-2022-36864
Samsung Email General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.