7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-27824
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-125 1 PoC

Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file

CVE-2022-33728
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via Settings.Gloabal.

CVE-2022-39871
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via implicit broadcasts.

CVE-2022-24002
Link sharing General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.

CVE-2022-28784
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-22 1 PoC

Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.

CVE-2022-33685
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-561 1 PoC

Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows attacker to launch arbitray activity and access senstive information.

CVE-2022-29945
Software Genérico General
4.0
MEDIUM
EPSS
0.2%
2022 1 PoC

DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator's physical location via the AeroScope protocol.

CVE-2022-28790
Link to Windows Service Windows
4.0
MEDIUM
EPSS
0.1%
2022 CWE-287 1 PoC

Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.

CVE-2022-3491
vim/vim General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.

CVE-2022-36854
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-20 1 PoC

Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized information.

CVE-2022-23995
Samsung Wearable Devices General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

CVE-2022-30737
Samsung Account General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.

CVE-2022-39848
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-213 1 PoC

Exposure of sensitive information in AT_Distributor prior to SMR Oct-2022 Release 1 allows local attacker to access SerialNo via log.

CVE-2022-27832
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.

CVE-2022-39851
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in CocktailBarService prior to SMR Oct-2022 Release 1 allows local attacker to bind service that require BIND_REMOTEVIEWS permission.

CVE-2022-39896
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.

CVE-2022-24923
SearchWidget General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

CVE-2022-36864
Samsung Email General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.

CVE-2022-39914
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.

CVE-2022-39870
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via PUSH_MESSAGE_RECEIVED broadcast.