Filtered by vendor Samsung
Subscribe
Total
932 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-26144 | 3 Arista, Samsung, Siemens | 36 C-100, C-100 Firmware, C-110 and 33 more | 2023-12-10 | 3.3 LOW | 6.5 MEDIUM |
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration. | |||||
CVE-2021-25416 | 2 Google, Samsung | 5 Android, Exynos 9610, Exynos 9810 and 2 more | 2023-12-10 | 2.1 LOW | 6.5 MEDIUM |
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area. | |||||
CVE-2021-25372 | 2 Google, Samsung | 4 Android, Exynos 2100, Exynos 980 and 1 more | 2023-12-10 | 7.2 HIGH | 6.7 MEDIUM |
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. | |||||
CVE-2021-25446 | 1 Samsung | 2 Smartthings, Smartthings Firmware | 2023-12-10 | 5.0 MEDIUM | 5.3 MEDIUM |
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview. | |||||
CVE-2021-25402 | 1 Samsung | 1 Notes | 2023-12-10 | 2.1 LOW | 3.3 LOW |
Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information. | |||||
CVE-2021-25431 | 2 Google, Samsung | 2 Android, Cameralyzer | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
Improper access control vulnerability in Cameralyzer prior to versions 3.2.1041 in 3.2.x, 3.3.1040 in 3.3.x, and 3.4.4210 in 3.4.x allows untrusted applications to access some functions of Cameralyzer. | |||||
CVE-2021-25374 | 2 Google, Samsung | 2 Android, Members | 2023-12-10 | 5.0 MEDIUM | 7.5 HIGH |
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account. | |||||
CVE-2021-25438 | 2 Google, Samsung | 2 Android, Members | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview. | |||||
CVE-2021-22684 | 1 Samsung | 1 Tizenrt | 2023-12-10 | 5.0 MEDIUM | 7.5 HIGH |
Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash | |||||
CVE-2021-25368 | 1 Samsung | 1 Cloud | 2023-12-10 | 5.0 MEDIUM | 7.5 HIGH |
Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed. | |||||
CVE-2021-25420 | 1 Samsung | 1 Galaxy Watch Plugin | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log. | |||||
CVE-2021-25404 | 1 Samsung | 2 Smartthings, Smartthings Firmware | 2023-12-10 | 2.1 LOW | 3.3 LOW |
Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log. | |||||
CVE-2021-25441 | 2 Google, Samsung | 2 Android, Ar Emoji Editor | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
Improper input validation vulnerability in AR Emoji Editor prior to version 4.4.03.5 in Android Q(10.0) and above allows untrusted applications to access arbitrary files with an escalated privilege. | |||||
CVE-2021-25354 | 1 Samsung | 1 Internet | 2023-12-10 | 6.8 MEDIUM | 5.3 MEDIUM |
Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink. | |||||
CVE-2021-25424 | 1 Samsung | 18 Galaxy Watch, Galaxy Watch 3, Galaxy Watch 3 Firmware and 15 more | 2023-12-10 | 5.8 MEDIUM | 8.8 HIGH |
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness. | |||||
CVE-2021-25440 | 1 Samsung | 1 Factorycamerafb | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an escalated privilege. | |||||
CVE-2021-25381 | 2 Google, Samsung | 2 Android, Account | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent. | |||||
CVE-2021-25373 | 2 Google, Samsung | 2 Android, Customization Service | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent. | |||||
CVE-2021-25423 | 1 Samsung | 1 Watch Active2 Plugin | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone via log. | |||||
CVE-2021-25376 | 1 Samsung | 1 Email | 2023-12-10 | 5.0 MEDIUM | 5.3 MEDIUM |
An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed. |