3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-28794
Samsung Mobile Devices General
2.2
LOW
EPSS
0.0%
2022 CWE-213 1 PoC

Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.

CVE-2022-24924
LiveWallpaper General
2.2
LOW
EPSS
2.9%
2022 CWE-284 2 PoCs

An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.

CVE-2022-25831
Samsung Mobile Devices General
2.0
LOW
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access secured data in certain conditions.

CVE-2022-33700
Samsung Mobile Devices General
2.0
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

CVE-2022-1002
Mattermost General
2.0
LOW
EPSS
0.2%
2022 CWE-80 1 PoC

Mattermost 6.3.0 and earlier fails to properly sanitize the HTML content in the email invitation sent to guest users, which allows registered users with special permissions to invite guest users to inject unescaped HTML content in the email invitations.

CVE-2022-33699
Samsung Mobile Devices General
2.0
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

CVE-2022-33693
Samsung Mobile Devices General
2.0
LOW
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

CVE-2022-23830
3rd Gen AMD EPYC™ Processors General
1.9
LOW
EPSS
0.1%
2022 2 PoCs

SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.

CVE-2022-25828
Watch Active PlugIn General
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information of connected WiFiAp in the log

CVE-2022-4610
Passwordstate General
1.9
LOW
EPSS
0.1%
2022 CWE-310 1 PoC

A vulnerability, which was classified as problematic, has been found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. Affected by this issue is some unknown functionality. The manipulation leads to risky cryptographic algorithm. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-216272.

CVE-2022-25829
Watch Active2 PlugIn General
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information of connected WiFiAp in the log

CVE-2022-36852
Samsung Mobile Devices General
1.9
LOW
EPSS
0.0%
2022 CWE-285 1 PoC

Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.

CVE-2022-25830
Galaxy Watch3 Plugin General
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log

CVE-2022-30728
Samsung Mobile Devices General
1.9
LOW
EPSS
0.0%
2022 CWE-213 1 PoC

Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

CVE-2022-25827
Galaxy Watch PlugIn General
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information of connected WiFiAp in the log

CVE-2022-36857
Samsung Mobile Devices General
1.9
LOW
EPSS
0.0%
2022 CWE-285 1 PoC

Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.

CVE-2022-30714
Samsung Mobile Devices General
1.9
LOW
EPSS
0.0%
2022 CWE-213 1 PoC

Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

CVE-2022-25823
Galaxy Watch Plugin General
1.9
LOW
EPSS
0.1%
2022 CWE-200 1 PoC

Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log.

CVE-2022-36876
Samsung Pass General
1.8
LOW
EPSS
0.1%
2022 CWE-285 1 PoC

Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.

CVE-2022-2008
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.