5391 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2025-21057
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.

CVE-2025-69418
OpenSSL Web
4.0
MEDIUM
EPSS
0.0%
2025 CWE-325 1 PoC

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact summary: The trailing 1-15 bytes of a message may be exposed in<br>cleartext on encryption and are not covered by the authentication tag,<br>allowing an attacker to read or tamper with those bytes without detection.<br><br>The low-level OCB encrypt and decrypt routines in the hardware-accelerated<br>stream path process full 16-byte blocks but do not

CVE-2025-21070
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

CVE-2025-21066
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

CVE-2025-21069
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

CVE-2025-20950
SamsungNotes General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.

CVE-2025-48708
Ghostscript General
4.0
MEDIUM
EPSS
0.0%
2025 CWE-212 1 PoC

gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.

CVE-2025-20909
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-21045
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-53910
Mattermost Confluence Plugin Web
4.0
MEDIUM
EPSS
0.1%
2025 CWE-862 1 PoC

Mattermost Confluence Plugin version <1.5.0 fails to check the access of the user to the channel which allows attackers to create a channel subscription without proper access to the channel via API call to the edit channel subscription endpoint.

CVE-2025-20960
Samsung Mobile Devices Web
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.

CVE-2025-21053
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

CVE-2025-21033
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.

CVE-2025-20945
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper access control in Galaxy Watch prior to SMR Apr-2025 Release 1 allows local attackers to access sensitive information of Galaxy watch.

CVE-2025-21015
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

CVE-2025-21034
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.

CVE-2025-21068
Samsung Notes General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

CVE-2025-21026
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.0%
2025 1 PoC

Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.

CVE-2025-20940
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2025 1 PoC

Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS.

CVE-2025-32365
Poppler General
4.0
MEDIUM
EPSS
0.1%
2025 CWE-125 1 PoC

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.