Lucene search

K
cvelistSamsung MobileCVELIST:CVE-2021-25496
HistoryOct 06, 2021 - 5:11 p.m.

CVE-2021-25496

2021-10-0617:11:26
CWE-120
Samsung Mobile
www.cve.org
5
buffer overflow
samsung notes
arbitrary code execution

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

EPSS

0

Percentile

5.1%

A possible buffer overflow vulnerability in maetd_dec_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.

CNA Affected

[
  {
    "product": "Samsung Notes",
    "vendor": "Samsung Mobile",
    "versions": [
      {
        "lessThan": "4.3.02.61",
        "status": "affected",
        "version": "-",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

EPSS

0

Percentile

5.1%

Related for CVELIST:CVE-2021-25496