Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Total 932 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30689 1 Samsung 1 Android 2023-12-10 N/A 7.8 HIGH
Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVE-2023-30718 1 Samsung 1 Android 2023-12-10 N/A 3.3 LOW
Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.
CVE-2023-42529 1 Samsung 1 Android 2023-12-10 N/A 7.8 HIGH
Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.
CVE-2020-22181 1 Samsung 2 Sww-3400rw, Sww-3400rw Firmware 2023-12-10 N/A 6.1 MEDIUM
A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi
CVE-2023-30685 1 Samsung 1 Android 2023-12-10 N/A 3.3 LOW
Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
CVE-2023-30737 1 Samsung 1 Health 2023-12-10 N/A 5.5 MEDIUM
Improper access control vulnerability in Samsung Health prior to version 6.24.3.007 allows attackers to access sensitive information via implicit intent.
CVE-2023-42528 1 Samsung 1 Android 2023-12-10 N/A 7.8 HIGH
Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.
CVE-2023-30697 1 Samsung 1 Android 2023-12-10 N/A 7.8 HIGH
An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
CVE-2023-30711 1 Samsung 1 Android 2023-12-10 N/A 3.3 LOW
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
CVE-2023-21488 1 Samsung 1 Android 2023-12-10 N/A 7.8 HIGH
Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.
CVE-2023-21504 1 Samsung 1 Android 2023-12-10 N/A 9.8 CRITICAL
Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
CVE-2023-30660 1 Samsung 1 Android 2023-12-10 N/A 5.5 MEDIUM
Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
CVE-2023-30677 1 Samsung 1 Pass 2023-12-10 N/A 4.6 MEDIUM
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.
CVE-2023-31114 1 Samsung 4 Exynos 5123, Exynos 5123 Firmware, Exynos 5300 and 1 more 2023-12-10 N/A 9.1 CRITICAL
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause unintended querying of the SIM status via a crafted application.
CVE-2023-21497 1 Samsung 1 Android 2023-12-10 N/A 7.8 HIGH
Use of externally-controlled format string vulnerability in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the memory address.
CVE-2023-30652 1 Samsung 1 Android 2023-12-10 N/A 7.8 HIGH
Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
CVE-2023-21498 1 Samsung 1 Android 2023-12-10 N/A 7.8 HIGH
Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.
CVE-2023-30669 1 Samsung 1 Android 2023-12-10 N/A 7.8 HIGH
Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
CVE-2023-30651 1 Samsung 1 Android 2023-12-10 N/A 7.8 HIGH
Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
CVE-2023-30674 1 Samsung 1 Internet 2023-12-10 N/A 6.5 MEDIUM
Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie.