7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-39914
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.

CVE-2022-30734
Samsung Account General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.

CVE-2022-30757
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain CID without ACCESS_FINE_LOCATION permission.

CVE-2022-27823
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-125 1 PoC

Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

CVE-2022-21494
Solaris Operating System Database
4.0
MEDIUM
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel). The supported version that is affected is 11. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 4.0 (Availability impacts). CVSS Vector: (CVSS:3.1

CVE-2022-39905
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-285 1 PoC

Implicit intent hijacking vulnerability in Telecom application prior to SMR Dec-2022 Release 1 allows attacker to access sensitive information via implicit intent.

CVE-2022-25481
Software Genérico Web ⚡ nuclei
4.0
MEDIUM
EPSS
9.5%
2022 0 PoCs

ThinkPHP Framework v5.0.24 was discovered to be configured without the PATHINFO parameter. This allows attackers to access all system environment parameters from index.php. NOTE: this is disputed by a third party because system environment exposure is an intended feature of the debugging mode.

CVE-2022-33694
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-213 1 PoC

Exposure of Sensitive Information in CSC application prior to SMR Jul-2022 Release 1 allows local attacker to access wifi information via unprotected intent broadcasting.

CVE-2022-39869
SmartThings Cloud
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information via REMOVE_PERSISTENT_BANNER broadcast.

CVE-2022-22266
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-269 1 PoC

(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.

CVE-2022-30745
Quick Share General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share.

CVE-2022-28788
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

Improper buffer size check logic in aviextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVE-2022-39903
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-200 1 PoC

Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.

CVE-2022-30717
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-285 1 PoC

Improper caller check in AR Emoji prior to SMR Jun-2022 Release 1 allows untrusted applications to use some camera functions via deeplink.

CVE-2022-24003
Bixby Vision General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-200 1 PoC

Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision via unprotected intent.

CVE-2022-30715
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2022 CWE-284 1 PoC

Improper access control vulnerability in DofViewer prior to SMR Jun-2022 Release 1 allows attackers to control floating system alert window.

CVE-2022-28787
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-125 1 PoC

Improper buffer size check logic in wmfextractor library prior to SMR May-2022 Release 1 allows out of bounds read leading to possible temporary denial of service. The patch adds buffer size check logic.

CVE-2022-39898
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2022 CWE-284 1 PoC

Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.

CVE-2022-30739
Samsung Account General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-269 1 PoC

Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.

CVE-2022-39877
Group Sharing General
4.0
MEDIUM
EPSS
0.2%
2022 CWE-284 1 PoC

Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.