Skip to main content

Vendor/product archive

samsung / android CVEs

Beta · best-effort

475 CVEs tagged to samsung / android1 Critical, 86 High, 367 Medium, 21 Low, 0 Unrated.

CVE-2023-30714

Published Sep 6, 2023

Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30713

Published Sep 6, 2023

Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30712

Published Sep 6, 2023

Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30711

Published Sep 6, 2023

Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30710

Published Sep 6, 2023

Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30709

Published Sep 6, 2023

Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30708

Published Sep 6, 2023

Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30707

Published Sep 6, 2023

Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Sam…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30706

Published Sep 6, 2023

Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read arbitrary file with system privilege.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30701

Published Aug 10, 2023

PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30700

Published Aug 10, 2023

PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permissi…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30699

Published Aug 10, 2023

Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30698

Published Aug 10, 2023

Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30697

Published Aug 10, 2023

An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30696

Published Aug 10, 2023

An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30694

Published Aug 10, 2023

Out-of-bounds Write in IpcTxPcscTransmitApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30693

Published Aug 10, 2023

Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30691

Published Aug 10, 2023

Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-30689

Published Aug 10, 2023

Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30688

Published Aug 10, 2023

Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30687

Published Aug 10, 2023

Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30686

Published Aug 10, 2023

Out-of-bounds Write in ReqDataRaw of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30685

Published Aug 10, 2023

Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30684

Published Aug 10, 2023

Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30683

Published Aug 10, 2023

Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 351-375 of 475 CVEsPage 15 of 19