2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-52516
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of service.

CVE-2025-21002
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.

CVE-2025-20912
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.

CVE-2025-20965
Voice wake-up General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.

CVE-2025-54409
aide General
6.2
MEDIUM
EPSS
0.0%
2025 CWE-476 1 PoC

AIDE is an advanced intrusion detection environment. From versions 0.13 to 0.19.1, there is a null pointer dereference vulnerability in AIDE. An attacker can crash the program during report printing or database listing after setting extended file attributes with an empty attribute value or with a key containing a comma. A local user might exploit this to cause a local denial of service. This issue has been patched in version 0.19.2. A workaround involves removing xattrs group from rules matching files on affected file systems.

CVE-2025-65410
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

A stack overflow in the src/main.c component of GNU Unrtf v0.21.10 allows attackers to cause a Denial of Service (DoS) via injecting a crafted input into the filename parameter.

CVE-2025-21013
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time.

CVE-2025-62686
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 on macOS. Due to the absence of a hardened runtime and a __RESTRICT segment, a local user may exploit the DYLD_INSERT_LIBRARIES environment variable to inject a dynamic library, potentially resulting in code execution with elevated privileges.

CVE-2025-20944
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.

CVE-2025-55076
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands with root privileges.

CVE-2025-58340
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_delts write operation, leading to kernel memory exhaustion.

CVE-2025-54389
aide General
6.2
MEDIUM
EPSS
0.0%
2025 CWE-117 1 PoC

AIDE is an advanced intrusion detection environment. Prior to version 0.19.2, there is an improper output neutralization vulnerability in AIDE. An attacker can craft a malicious filename by including terminal escape sequences to hide the addition or removal of the file from the report and/or tamper with the log output. A local user might exploit this to bypass the AIDE detection of malicious files. Additionally the output of extended attribute key names and symbolic links targets are also not properly neutralized. This issue has been patched in version 0.19.2. A workaround involves configurin

CVE-2025-58341
Software Genérico General
6.2
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_cert_disable_ht_vht write operation, leading to kernel memory exhaustion.

CVE-2025-20972
Samsung Flow General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.

CVE-2025-21041
Secure Folder General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.

CVE-2025-20941
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.

CVE-2025-0395
glibc General
6.2
MEDIUM
EPSS
0.1%
2025 CWE-131 4 PoCs

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.

CVE-2025-20981
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-21004
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.

CVE-2025-20978
PENUP General
6.2
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.