2528 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2025-24182
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2025 3 PoCs

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a maliciously crafted font may result in the disclosure of process memory.

CVE-2025-20952
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.

CVE-2025-24276
macOS General
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.

CVE-2025-58346
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_addts write operation, leading to kernel memory exhaustion.

CVE-2025-58347
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/p2p_certif write operation, leading to kernel memory exhaustion.

CVE-2025-30454
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, tvOS 18.4, watchOS 11.4. A malicious app may be able to access private information.

CVE-2025-48561
Android General
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

In multiple locations, there is a possible way to access data displayed on the screen due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-31187
macOS General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to modify protected parts of the file system.

CVE-2025-21019
Samsung Health General
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.

CVE-2025-21922
Linux General
5.5
MEDIUM
EPSS
0.1%
2025 2 PoCs

In the Linux kernel, the following vulnerability has been resolved: ppp: Fix KMSAN uninit-value warning with bpf Syzbot caught an "KMSAN: uninit-value" warning [1], which is caused by the ppp driver not initializing a 2-byte header when using socket filter. The following code can generate a PPP filter BPF program: ''' struct bpf_program fp; pcap_t *handle; handle = pcap_open_dead(DLT_PPP_PPPD, 65535); pcap_compile(handle, &fp, "ip and outbound", 0, 0); bpf_dump(&fp, 1); ''' Its output is: ''' (000) ldh [2] (001) jeq #0x21 jt 2 jf 5 (002) ldb [0] (003) jeq #0x1 jt 4 jf 5 (004) ret #65535 (00

CVE-2025-24163
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2025 3 PoCs

The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sequoia 15.4, macOS Sonoma 14.7.3, tvOS 18.3, tvOS 18.4, visionOS 2.3, visionOS 2.4, watchOS 11.3, watchOS 11.4. Parsing a file may lead to an unexpected app termination.

CVE-2025-20921
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVE-2025-30450
macOS General
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access sensitive user data.

CVE-2025-31191
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.1%
2025 4 PoCs

This issue was addressed through improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.

CVE-2025-20998
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.

CVE-2025-30470
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2025 3 PoCs

A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, visionOS 2.4, watchOS 11.4. An app may be able to read sensitive location information.

CVE-2025-20915
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVE-2025-20916
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Out-of-bounds read in reading string of SPen in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVE-2025-20976
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to read out-of-bounds memory.

CVE-2025-20969
Samsung Gallery General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows local attackers to access data within Samsung Gallery.