5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0696
vim/vim General
6.2
MEDIUM
EPSS
0.2%
2022 CWE-476 2 PoCs

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.

CVE-2022-39846
Smart Switch PC General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-427 1 PoC

DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.

CVE-2022-25876
link-preview-js General
6.2
MEDIUM
EPSS
0.1%
2022 1 PoC

The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.

CVE-2022-30726
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.

CVE-2022-36829
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

CVE-2022-30727
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.

CVE-2022-33733
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

Sensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.

CVE-2022-33732
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.

CVE-2022-43380
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-399 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX NFS kernel extension to cause a denial of service. IBM X-Force ID: 238640.

CVE-2022-33734
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

Sensitive information exposure in onCharacteristicChanged in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.

CVE-2022-28791
Galaxy Store General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.

CVE-2022-39890
Samsung Billing General
6.2
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.

CVE-2022-43849
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX pfcdd kernel extension to cause a denial of service. IBM X-Force ID: 239170.

CVE-2022-36836
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.

CVE-2022-28544
Galaxy Store General
6.2
MEDIUM
EPSS
0.3%
2022 CWE-22 1 PoC

Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.

CVE-2022-36837
Samsung email General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.

CVE-2022-39912
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

CVE-2022-23998
Samsung Camera General
6.2
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.

CVE-2022-39164
AIX General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 235181.

CVE-2022-42284
NVIDIA DGX servers General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-312 1 PoC

NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.