5091 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-21026
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.

CVE-2025-32365
Poppler General
4.0
MEDIUM
EPSS
0.1%
2025 CWE-125 1 PoC

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

CVE-2025-20923
Galaxy Wearable General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Galaxy Wearable prior to version 2.2.61.24112961 allows local attackers to launch arbitrary activity with Galaxy Wearable privilege.

CVE-2025-21003
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-21029
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.

CVE-2025-20991
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.

CVE-2025-55631
Software Genérico General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to manage users' sessions system wide instead of an account-by-account basis, potentially leading to a Denial of Service (DoS) via resource exhaustion. NOTE: the Supplier reports that the system-wide limit is intentional.

CVE-2025-20990
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.

CVE-2025-32056
Infotainment system ECU General
4.0
MEDIUM
EPSS
0.0%
2025 CWE-1241 2 PoCs

The anti-theft protection mechanism can be bypassed by attackers due to weak response generation algorithms for the head unit. It is possible to reveal all 32 corresponding responses by sniffing CAN traffic or by pre-calculating the values, which allow to bypass the protection. First identified on Nissan Leaf ZE1 manufactured in 2020.

CVE-2025-21070
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

CVE-2025-48708
Ghostscript General
4.0
MEDIUM
EPSS
0.0%
2025 CWE-212 1 PoC

gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.

CVE-2025-21045
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-53910
Mattermost Confluence Plugin Web
4.0
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint.

CVE-2025-21053
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

CVE-2025-20945
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.

CVE-2025-21015
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

CVE-2025-21068
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

CVE-2025-26417
Android General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

In checkWhetherCallingAppHasAccess of DownloadProvider.java, there is a possible bypass of user consent when opening files in shared storage due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-20993
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2025-20962
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.