5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-28786
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVE-2022-39851
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.

CVE-2022-36864
Samsung Email General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.

CVE-2022-39883
Samsung Mobile Devices Web
4.0
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.

CVE-2022-39856
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Improper access control vulnerability in imsservice application prior to SMR Oct-2022 Release 1 allows local attackers to access call information.

CVE-2022-25832
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-287 1 PoC

Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication.

CVE-2022-30734
Samsung Account General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.

CVE-2022-33694
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-213 1 PoC

Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wifi information via unprotected intent broadcasting.

CVE-2022-28785
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVE-2022-33722
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC address.

CVE-2022-29945
Software Genérico General
4.0
MEDIUM
EPSS
0.2%
2022 1 PoC

DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.

CVE-2022-36854
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.

CVE-2022-23995
Samsung Wearable Devices General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

CVE-2022-39848
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-213 1 PoC

Exposure of sensitive information in AT_Distributor prior to SMR Oct-2022 Release 1 allows local attacker to access SerialNo via log.

CVE-2022-27823
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-125 1 PoC

Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

CVE-2022-21494
Solaris Operating System Database
4.0
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 4.0 (Availability impacts). CVSS Vector: (CVSS:3.1

CVE-2022-39905
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.

CVE-2022-25481
Software Genérico Web ⚡ nuclei
4.0
MEDIUM
EPSS
9.5%
2022 0 PoCs

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

CVE-2022-24003
Bixby Vision General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision via unprotected intent.

CVE-2022-39898
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.