5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-30739
Samsung Account General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-269 1 PoC

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.

CVE-2022-39868
SmartThings General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcast.

CVE-2022-27821
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-125 1 PoC

Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via crafted image file.

CVE-2022-30758
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-276 1 PoC

Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to access some protected information with privilege of Finder.

CVE-2022-30733
Samsung Account General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.

CVE-2022-39874
Samsung Account General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-779 1 PoC

Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

CVE-2022-25822
Samsung Mobile devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-362 1 PoC

An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.

CVE-2022-30725
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Broadcasting Intent including the BluetoothDevice object without proper restriction of receivers in sendIntentSessionError function of Bluetooth prior to SMR Jun-2022 Release 1 leaks MAC address of the connected Bluetooth device.

CVE-2022-39859
UPHelper General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-200 1 PoC

Implicit intent hijacking vulnerability in UPHelper library prior to version 3.0.12 allows attackers to access sensitive information via implicit intent.

CVE-2022-30716
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-280 1 PoC

Unprotected broadcast in sendIntentForToastDumpLog in DisplayToast prior to SMR Jun-2022 Release 1 allows untrusted applications to access toast message information from device.

CVE-2022-28784
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-22 1 PoC

Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.

CVE-2022-28790
Link to Windows Service Windows
4.0
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

CVE-2022-30737
Samsung Account General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.

CVE-2022-27832
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.

CVE-2022-24923
SearchWidget General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

CVE-2022-39914
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.

CVE-2022-39869
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.

CVE-2022-22266
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-269 1 PoC

(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.

CVE-2022-30745
Quick Share General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share.

CVE-2022-39903
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.