Lucene search

K

Samsung Mobile Devices Security Vulnerabilities

cve
cve

CVE-2022-39849

Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration...

3.3CVSS

4AI Score

0.0004EPSS

2022-10-07 03:15 PM
27
3
cve
cve

CVE-2022-39850

Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration...

3.3CVSS

4AI Score

0.0004EPSS

2022-10-07 03:15 PM
21
5
cve
cve

CVE-2022-36868

Improper restriction of broadcasting Intent in MouseNKeyHidDevice prior to SMR Oct-2022 Release 1 leaks MAC address of the connected Bluetooth...

5.9CVSS

4.1AI Score

0.0004EPSS

2022-10-07 03:15 PM
25
2
cve
cve

CVE-2022-36858

A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc() function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
23
2
cve
cve

CVE-2022-36863

A heap-based overflow vulnerability in GetCorrectDbLanguageTypeEsPKc function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
40
5
cve
cve

CVE-2022-36861

Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows attacker to use some protected functions with SystemUI...

5.9CVSS

5.2AI Score

0.0004EPSS

2022-09-09 03:15 PM
24
4
cve
cve

CVE-2022-36862

A heap-based overflow vulnerability in HWR::EngineCJK::Impl::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
31
5
cve
cve

CVE-2022-36860

A heap-based overflow vulnerability in LoadEnvironment function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
32
2
cve
cve

CVE-2022-36847

Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious...

7.8CVSS

7.8AI Score

0.0004EPSS

2022-09-09 03:15 PM
25
4
cve
cve

CVE-2022-36843

A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
26
4
cve
cve

CVE-2022-36853

Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive...

7.5CVSS

7.4AI Score

0.001EPSS

2022-09-09 03:15 PM
25
4
cve
cve

CVE-2022-36852

Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application...

3.3CVSS

3.9AI Score

0.0004EPSS

2022-09-09 03:15 PM
24
4
cve
cve

CVE-2022-36857

Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application...

2.4CVSS

3.7AI Score

0.0004EPSS

2022-09-09 03:15 PM
23
4
cve
cve

CVE-2022-36856

Improper access control vulnerability in Telecom application prior to SMR Sep-2022 Release 1 allows attacker to start emergency calls via undefined...

4CVSS

4.1AI Score

0.0004EPSS

2022-09-09 03:15 PM
13
4
cve
cve

CVE-2022-36844

A heap-based overflow vulnerability in HWR::EngJudgeModel::Construct() in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
20
4
cve
cve

CVE-2022-36846

A heap-based overflow vulnerability in ConstructDictionary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
29
4
cve
cve

CVE-2022-36854

Out of bound read in libapexjni.media.samsung.so prior to SMR Sep-2022 Release 1 allows attacker access unauthorized...

5.5CVSS

5.3AI Score

0.0004EPSS

2022-09-09 03:15 PM
27
4
cve
cve

CVE-2022-36855

A use after free vulnerability in iva_ctl driver prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
25
4
cve
cve

CVE-2022-36848

Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of...

5.5CVSS

5.3AI Score

0.0004EPSS

2022-09-09 03:15 PM
26
4
cve
cve

CVE-2022-36845

A heap-based overflow vulnerability in MHW_RECOG_LIB_INFO function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
27
4
cve
cve

CVE-2022-36850

Path traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary file with phone...

4.7CVSS

4.8AI Score

0.0004EPSS

2022-09-09 03:15 PM
43
4
cve
cve

CVE-2022-36849

Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious...

7.8CVSS

7.8AI Score

0.0004EPSS

2022-09-09 03:15 PM
26
4
cve
cve

CVE-2022-36842

A heap-based overflow vulnerability in prepareRecogLibrary function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
24
6
cve
cve

CVE-2022-36841

A heap-based overflow vulnerability in PrepareRecogLibrary_Part function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR Sep-2022 Release 1 allows attacker to cause memory access...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-09-09 03:15 PM
24
6
cve
cve

CVE-2022-33732

Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder...

7.1CVSS

6.8AI Score

0.0004EPSS

2022-08-05 04:15 PM
35
2
cve
cve

CVE-2022-33731

Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary...

7.1CVSS

6.9AI Score

0.0004EPSS

2022-08-05 04:15 PM
29
4
cve
cve

CVE-2022-33730

Heap-based buffer overflow vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows arbitrary code execution by physical...

6.8CVSS

7AI Score

0.001EPSS

2022-08-05 04:15 PM
41
cve
cve

CVE-2022-33729

Improper restriction of broadcasting Intent in ConfirmConnectActivity of?NFC prior to SMR Aug-2022 Release 1 leaks MAC address of the connected Bluetooth...

5.9CVSS

4.1AI Score

0.0004EPSS

2022-08-05 04:15 PM
74
4
cve
cve

CVE-2022-33716

An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitialized...

4.4CVSS

4.5AI Score

0.0004EPSS

2022-08-05 04:15 PM
36
cve
cve

CVE-2022-33717

A missing input validation before memory read in SEM TA prior to SMR Aug-2022 Release 1 allows local attackers to read out of bound...

4.4CVSS

4.5AI Score

0.0004EPSS

2022-08-05 04:15 PM
34
cve
cve

CVE-2022-33720

Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap...

2.4CVSS

3.9AI Score

0.0005EPSS

2022-08-05 04:15 PM
37
cve
cve

CVE-2022-33721

A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system...

5.5CVSS

5.5AI Score

0.0004EPSS

2022-08-05 04:15 PM
35
4
cve
cve

CVE-2022-33719

Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap...

9.8CVSS

9.4AI Score

0.001EPSS

2022-08-05 04:15 PM
38
cve
cve

CVE-2022-33718

An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile...

6.2CVSS

4.1AI Score

0.0004EPSS

2022-08-05 04:15 PM
32
4
cve
cve

CVE-2022-33727

A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay...

6.1CVSS

6.3AI Score

0.001EPSS

2022-08-05 04:15 PM
34
4
cve
cve

CVE-2022-33728

Exposure of sensitive information in Bluetooth prior to SMR Aug-2022 Release 1 allows local attackers to access connected BT macAddress via...

4CVSS

3.8AI Score

0.0004EPSS

2022-08-05 04:15 PM
31
cve
cve

CVE-2022-33723

A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay...

6.1CVSS

6.3AI Score

0.001EPSS

2022-08-05 04:15 PM
40
4
cve
cve

CVE-2022-33722

Implicit Intent hijacking vulnerability in Smart View prior to SMR Aug-2022 Release 1 allows attacker to access connected device MAC...

4CVSS

4.1AI Score

0.0004EPSS

2022-08-05 04:15 PM
29
2
cve
cve

CVE-2022-33715

Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of One...

5.5CVSS

5.4AI Score

0.0004EPSS

2022-08-05 04:15 PM
40
cve
cve

CVE-2022-33726

Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch...

3.3CVSS

4.1AI Score

0.0004EPSS

2022-08-05 04:15 PM
29
4
cve
cve

CVE-2022-33724

Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via...

3.3CVSS

4AI Score

0.0004EPSS

2022-08-05 04:15 PM
37
cve
cve

CVE-2022-33714

Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile...

6.2CVSS

4AI Score

0.0004EPSS

2022-08-05 04:15 PM
37
4
cve
cve

CVE-2022-33725

A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to access content providers with system...

4CVSS

4.1AI Score

0.0004EPSS

2022-08-05 04:15 PM
34
4
cve
cve

CVE-2022-33703

Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain...

8.5CVSS

7.5AI Score

0.0004EPSS

2022-07-12 02:15 PM
51
3
cve
cve

CVE-2022-33704

Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain...

8.5CVSS

7.5AI Score

0.0004EPSS

2022-07-12 02:15 PM
32
3
cve
cve

CVE-2022-33695

Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the...

7.8CVSS

7.5AI Score

0.0004EPSS

2022-07-12 02:15 PM
23
2
cve
cve

CVE-2022-33688

Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device...

3.3CVSS

3.7AI Score

0.0004EPSS

2022-07-12 02:15 PM
34
6
cve
cve

CVE-2022-33693

Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via...

2.3CVSS

3.7AI Score

0.0004EPSS

2022-07-12 02:15 PM
32
2
cve
cve

CVE-2022-33692

Exposure of Sensitive Information in Messaging application prior to SMR Jul-2022 Release 1 allows local attacker to access imsi and iccid via...

4CVSS

3.9AI Score

0.0004EPSS

2022-07-12 02:15 PM
36
4
cve
cve

CVE-2022-33689

Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder...

6.2CVSS

4AI Score

0.0004EPSS

2022-07-12 02:15 PM
29
4
Total number of security vulnerabilities549