3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-27576
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission

CVE-2022-39915
Samsung Calendar General
3.3
LOW
EPSS
0.1%
2022 CWE-284 2 PoCs

Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent.

CVE-2022-30729
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-923 1 PoC

Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner.

CVE-2022-30742
Find My Mobile General
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log.

CVE-2022-30753
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.

CVE-2022-39864
SmartThings General
3.3
LOW
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.

CVE-2022-33697
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-532 1 PoC

Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

CVE-2022-39904
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.

CVE-2022-37379
PDF Reader General
3.3
LOW
EPSS
0.9%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the AFSpecial_KeystrokeEx method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current pr

CVE-2022-33726
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-561 1 PoC

Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.

CVE-2022-36853
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2022 CWE-20 1 PoC

Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.

CVE-2022-24368
PDF Reader General
3.3
LOW
EPSS
0.5%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16

CVE-2022-36878
Find My Mobile General
3.3
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log.

CVE-2022-33688
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-532 1 PoC

Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

CVE-2022-37382
PDF Reader General
3.3
LOW
EPSS
0.9%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the removeIcon method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-17383.

CVE-2022-33687
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.

CVE-2022-30749
Smart Things General
3.3
LOW
EPSS
0.0%
2022 CWE-287 1 PoC

Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.

CVE-2022-33981
Software Genérico General
3.3
LOW
EPSS
0.0%
2022 2 PoCs

drivers/block/floppy.c in the Linux kernel before 5.17.6 is vulnerable to a denial of service, because of a concurrency use-after-free flaw after deallocating raw_cmd in the raw_cmd_ioctl function.

CVE-2022-24370
PDF Reader General
3.3
LOW
EPSS
0.5%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of XFA forms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context o

CVE-2022-33701
Samsung Mobile Devices General
3.3
LOW
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.