3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-28787
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVE-2022-33692
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-213 1 PoC

Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via log.

CVE-2022-28785
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVE-2022-39878
Samsung Checkout General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via implicit intent broadcast.

CVE-2022-39894
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.

CVE-2022-25822
Samsung Mobile devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-362 1 PoC

An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.

CVE-2022-22272
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission

CVE-2022-27825
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-125 1 PoC

Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

CVE-2022-30725
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVE-2022-36866
Group Sharing General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.

CVE-2022-23996
Samsung Wearable Devices General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.

CVE-2022-25832
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication.

CVE-2022-22267
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.

CVE-2022-30723
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in activateVoiceRecognitionWithDevice function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVE-2022-30748
Samsung Members General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-561 1 PoC

Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity.

CVE-2022-33722
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.

CVE-2022-22263
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-269 1 PoC

Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.

CVE-2022-36838
Galaxy Wearable General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Implicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information.

CVE-2022-25817
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.

CVE-2022-39859
UPHelper General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

Implicit intent hijacking vulnerability in UPHelper library prior to version 3.0.12 allows attackers to access sensitive information via implicit intent.