3431 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2021-25391
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-926 2 PoCs

Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

CVE-2021-25493
Samsung Notes General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-125 1 PoC

Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read

CVE-2021-25379
Gallery General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-926 2 PoCs

Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.

CVE-2021-46677
Pandora FMS Web
4.0
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the event filter name field.

CVE-2021-25504
Group Sharing General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-20 1 PoC

Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.

CVE-2021-25463
PENUP General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-284 1 PoC

Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.

CVE-2021-25461
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-120 2 PoCs

An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.

CVE-2021-25483
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-125 1 PoC

Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.

CVE-2021-25494
Samsung Notes General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-125 1 PoC

A possible buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.

CVE-2021-46681
Pandora FMS Web
4.0
MEDIUM
EPSS
0.3%
2021 CWE-79 1 PoC

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via module massive operation name field.

CVE-2021-25341
S Assistant General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-287 2 PoCs

Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider.

CVE-2021-25521
Samsung Internet General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-285 1 PoC

Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.

CVE-2021-25390
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-926 2 PoCs

Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

CVE-2021-25506
Samsung Health General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-287 1 PoC

Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.

CVE-2021-21781
Linux Kernel General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-908 2 PoCs

An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a process’s memory at a specific offset to trigger this vulnerability. This was fixed in kernel releases: 4.14.222 4.19.177 5.4.99 5.10.17 5.11

CVE-2021-46680
Pandora FMS Web
4.0
MEDIUM
EPSS
0.4%
2021 CWE-79 1 PoC

A XSS vulnerability exist in Pandora FMS version 756 and below, that allows an attacker to perform javascript code executions via the module form name field.

CVE-2021-25472
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-264 1 PoC

An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.

CVE-2021-25342
SMP sdk General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-287 2 PoCs

Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.

CVE-2021-25523
SamsungDialer General
4.0
MEDIUM
EPSS
0.1%
2021 CWE-922 1 PoC

Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.

CVE-2021-25358
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2021 CWE-256 2 PoCs

A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.