7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-43590
CBFS Filter General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-476 1 PoC

A null pointer dereference vulnerability exists in the handle_ioctl_0x830a0_systembuffer functionality of Callback technologies CBFS Filter 20.0.8317. A specially crafted I/O request packet (IRP) can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability.

CVE-2022-33733
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

Sensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.

CVE-2022-30722
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.

CVE-2022-23998
Samsung Camera General
6.2
MEDIUM
EPSS
0.2%
2022 CWE-20 1 PoC

Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.

CVE-2022-43848
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service. IBM X-Force ID: 239169.

CVE-2022-39164
AIX General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-400 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 235181.

CVE-2022-30727
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.

CVE-2022-25664
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables General
6.2
MEDIUM
EPSS
0.2%
2022 1 PoC

Information disclosure due to exposure of information while GPU reads the data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

CVE-2022-42284
NVIDIA DGX servers General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-312 1 PoC

NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.

CVE-2022-36829
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

CVE-2022-27843
Kies General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.

CVE-2022-28544
Galaxy Store General
6.2
MEDIUM
EPSS
0.3%
2022 CWE-22 1 PoC

Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.

CVE-2022-30726
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.

CVE-2022-36836
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-862 1 PoC

Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.

CVE-2022-25876
link-preview-js General
6.2
MEDIUM
EPSS
0.1%
2022 1 PoC

The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.

CVE-2022-39912
Samsung Mobile Devices General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-280 1 PoC

Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

CVE-2022-43380
AIX General
6.2
MEDIUM
EPSS
0.0%
2022 CWE-399 1 PoC

IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX NFS kernel extension to cause a denial of service. IBM X-Force ID: 238640.

CVE-2022-39186
BV-10 Performance Endpoint Unit General
6.2
MEDIUM
EPSS
0.0%
2022 1 PoC

EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions

CVE-2022-36830
Charm by Samsung General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-927 1 PoC

PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

CVE-2022-27842
Smart Switch PC General
6.2
MEDIUM
EPSS
0.1%
2022 CWE-20 1 PoC

DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.