5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-20971
Samsung Flow General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.

CVE-2025-52886
poppler General
5.5
MEDIUM
EPSS
0.3%
2025 CWE-416 2 PoCs

Poppler is a PDF rendering library. Versions prior to 25.06.0 use `std::atomic_int` for reference counting. Because `std::atomic_int` is only 32 bits, it is possible to overflow the reference count and trigger a use-after-free. Version 25.06.0 patches the issue.

CVE-2025-20933
Samsung Notes General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds read in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-of-bounds memory.

CVE-2025-20947
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.

CVE-2025-69619
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

A path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.

CVE-2025-24217
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, watchOS 11.4. An app may be able to access sensitive user data.

CVE-2025-20961
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.

CVE-2025-48607
Android General
5.5
MEDIUM
EPSS
0.0%
2025 1 PoC

In multiple locations, there is a possible way to create a large amount of app ops due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2025-20913
Samsung Notes General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVE-2025-24214
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2025 3 PoCs

A privacy issue was addressed by not logging contents of text fields. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. An app may be able to access sensitive user data.

CVE-2025-58343
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/create_tspec write operation, leading to kernel memory exhaustion.

CVE-2025-20988
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.

CVE-2025-20927
Samsung Notes General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Out-of-bounds read in parsing image data in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access out-of-bounds memory.

CVE-2025-58348
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2025 2 PoCs

An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/confg_tspec write operation, leading to kernel memory exhaustion.

CVE-2025-20975
AODService General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to launch arbitrary activity with systemui privilege.

CVE-2025-20917
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Out-of-bounds read in applying binary of pdf content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVE-2025-20914
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2025 1 PoC

Out-of-bounds read in applying binary of hand writing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.

CVE-2025-24104
iOS and iPadOS General
5.5
MEDIUM
EPSS
3.3%
2025 2 PoCs

This issue was addressed with improved handling of symlinks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4. Restoring a maliciously crafted backup file may lead to modification of protected system files.

CVE-2025-45250
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2025 2 PoCs

MrDoc v0.95 and before is vulnerable to Server-Side Request Forgery (SSRF) in the validate_url function of the app_doc/utils.py file.

CVE-2025-24278
macOS General
5.5
MEDIUM
EPSS
0.1%
2025 1 PoC

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to access protected user data.