3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-39164
AIX General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 235181.

CVE-2022-0240
mruby/mruby General
6.2
MEDIUM
EPSS
0.3%
2022 CWE-476 1 PoC

mruby is vulnerable to NULL Pointer Dereference

CVE-2022-33733
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

Sensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.

CVE-2022-43589
CBFS Filter General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

A null pointer dereference vulnerability exists in the handle_ioctl_8314C functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability.

CVE-2022-23998
Samsung Camera General
6.2
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.

CVE-2022-43485
OneWireless General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-330 1 PoC

Use of Insufficiently Random Values in Honeywell OneWireless. This vulnerability may allow attacker to manipulate claims in client's JWT token. This issue affects OneWireless version 322.1

CVE-2022-25825
Samsung Account General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.

CVE-2022-30727
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.

CVE-2022-20360
Android General
6.2
MEDIUM
EPSS
0.0%
2022 2 PoCs

In setChecked of SecureNfcPreferenceController.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228314987

CVE-2022-36829
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

CVE-2022-33718
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-863 1 PoC

An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.

CVE-2022-30726
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.

CVE-2022-28791
Galaxy Store General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.

CVE-2022-39912
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

CVE-2022-36831
Samsung notes General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-22 1 PoC

Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.

CVE-2022-33734
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

Sensitive information exposure in onCharacteristicChanged in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.

CVE-2022-28789
Voice Note General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper permission for vulnerable activities.

CVE-2022-28783
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

CVE-2022-25876
link-preview-js General
6.2
MEDIUM
EPSS
0.1%
2022 1 PoC

The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.

CVE-2022-43849
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX pfcdd kernel extension to cause a denial of service. IBM X-Force ID: 239170.