Lucene search

K

Samsung Mobile Security Vulnerabilities

cve
cve

CVE-2023-21489

Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary...

7.1CVSS

6.8AI Score

0.001EPSS

2023-05-04 09:15 PM
15
cve
cve

CVE-2023-21486

Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in...

5.3CVSS

4.5AI Score

0.001EPSS

2023-05-04 09:15 PM
15
cve
cve

CVE-2023-28613

An issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for Exynos 1280, Exynos 2200, and Exynos Modem 5300. An integer overflow in IPv4 fragment handling can occur due to insufficient parameter validation when reassembling these...

9.8CVSS

9.5AI Score

0.003EPSS

2023-04-04 04:15 PM
17
cve
cve

CVE-2023-26496

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5124. Memory corruption can occur due to improper checking of the parameter length while parsing the fmtp attribute in the SDP (Session Description...

9.8CVSS

9.6AI Score

0.002EPSS

2023-03-23 02:15 AM
42
cve
cve

CVE-2023-26498

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, Exynos Auto T5126. Memory corruption can occur due to improper checking of the number of properties while parsing the chatroom attribute in the SDP (Session Description...

9.8CVSS

9.6AI Score

0.002EPSS

2023-03-23 01:15 AM
45
cve
cve

CVE-2023-26497

An issue was discovered in Samsung Baseband Modem Chipset for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T5125. Memory corruption can occur when processing Session Description Negotiation for Video Configuration...

9.8CVSS

9.6AI Score

0.001EPSS

2023-03-21 10:15 PM
62
cve
cve

CVE-2023-21457

Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related...

8.1CVSS

7.9AI Score

0.0004EPSS

2023-03-16 09:15 PM
16
cve
cve

CVE-2023-21449

Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper...

5.5CVSS

5.2AI Score

0.0004EPSS

2023-03-16 09:15 PM
13
cve
cve

CVE-2023-21453

Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected...

6CVSS

5.3AI Score

0.0004EPSS

2023-03-16 09:15 PM
17
cve
cve

CVE-2023-21455

Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted...

9.1CVSS

9AI Score

0.001EPSS

2023-03-16 09:15 PM
21
cve
cve

CVE-2023-21458

Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected...

6.2CVSS

4.1AI Score

0.0004EPSS

2023-03-16 09:15 PM
19
cve
cve

CVE-2023-21459

Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access...

9.8CVSS

9.4AI Score

0.001EPSS

2023-03-16 09:15 PM
22
cve
cve

CVE-2023-21460

Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the...

4.4CVSS

4.8AI Score

0.0004EPSS

2023-03-16 09:15 PM
21
cve
cve

CVE-2023-21465

Improper access control vulnerability in BixbyTouch prior to version 3.2.02.5 in China models allows untrusted applications access local...

5.5CVSS

5.4AI Score

0.001EPSS

2023-03-16 09:15 PM
15
cve
cve

CVE-2023-21461

Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected...

5.5CVSS

5.3AI Score

0.0004EPSS

2023-03-16 09:15 PM
17
cve
cve

CVE-2023-21464

Improper access control in Samsung Calendar prior to versions 12.4.02.9000 in Android 13 and 12.3.08.2000 in Android 12 allows local attacker to configure improper...

4CVSS

4AI Score

0.0004EPSS

2023-03-16 09:15 PM
18
cve
cve

CVE-2023-21463

Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific...

4CVSS

3.7AI Score

0.0004EPSS

2023-03-16 09:15 PM
16
cve
cve

CVE-2023-21462

The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related...

4.2CVSS

3.7AI Score

0.0004EPSS

2023-03-16 09:15 PM
21
cve
cve

CVE-2023-21452

Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected...

3.3CVSS

4.1AI Score

0.0004EPSS

2023-03-16 09:15 PM
15
cve
cve

CVE-2023-21454

Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the...

2.4CVSS

3.8AI Score

0.0004EPSS

2023-03-16 09:15 PM
11
cve
cve

CVE-2023-21456

Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system...

9CVSS

5.5AI Score

0.0004EPSS

2023-03-16 09:15 PM
24
cve
cve

CVE-2023-26076

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G SM message codec can occur due to insufficient parameter validation when decoding reserved...

9.8CVSS

9.5AI Score

0.002EPSS

2023-03-13 03:15 PM
15
cve
cve

CVE-2023-26074

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123.. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient...

9.8CVSS

9.6AI Score

0.003EPSS

2023-03-13 01:15 PM
20
cve
cve

CVE-2023-26072

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient...

9.8CVSS

9.6AI Score

0.003EPSS

2023-03-13 12:15 PM
39
cve
cve

CVE-2023-26073

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. A heap-based buffer overflow in the 5G MM message codec can occur due to insufficient...

9.8CVSS

9.6AI Score

0.003EPSS

2023-03-13 02:15 PM
38
cve
cve

CVE-2023-26075

An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G MM message codec can occur due to insufficient parameter...

9.8CVSS

9.5AI Score

0.003EPSS

2023-03-10 05:15 PM
21
cve
cve

CVE-2023-21437

Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit...

5.5CVSS

5.2AI Score

0.0004EPSS

2023-02-09 07:15 PM
21
cve
cve

CVE-2023-21430

An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access...

7.8CVSS

7.3AI Score

0.0004EPSS

2023-02-09 07:15 PM
14
cve
cve

CVE-2023-21429

Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access...

4CVSS

4.1AI Score

0.0004EPSS

2023-02-09 07:15 PM
14
cve
cve

CVE-2023-21426

Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation...

5.5CVSS

5.4AI Score

0.0004EPSS

2023-02-09 07:15 PM
21
cve
cve

CVE-2023-21440

Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen...

6.2CVSS

5.4AI Score

0.001EPSS

2023-02-09 07:15 PM
28
cve
cve

CVE-2023-21441

Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused...

7.4CVSS

5.2AI Score

0.0004EPSS

2023-02-09 07:15 PM
21
cve
cve

CVE-2023-21439

Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain...

8.5CVSS

7.5AI Score

0.0004EPSS

2023-02-09 07:15 PM
20
cve
cve

CVE-2023-21438

Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure...

2.4CVSS

3.7AI Score

0.0004EPSS

2023-02-09 07:15 PM
25
cve
cve

CVE-2023-21442

Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location...

5.5CVSS

5.3AI Score

0.0004EPSS

2023-02-09 07:15 PM
15
cve
cve

CVE-2023-21436

Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account...

3.3CVSS

4.1AI Score

0.0004EPSS

2023-02-09 07:15 PM
18
cve
cve

CVE-2023-21423

Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected...

5.5CVSS

5.4AI Score

0.0004EPSS

2023-02-09 07:15 PM
16
cve
cve

CVE-2023-21422

Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding...

5.7CVSS

5.4AI Score

0.0004EPSS

2023-02-09 07:15 PM
14
cve
cve

CVE-2023-21435

Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via...

5.5CVSS

5.3AI Score

0.0004EPSS

2023-02-09 07:15 PM
18
cve
cve

CVE-2023-21428

Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused...

4CVSS

4.1AI Score

0.0004EPSS

2023-02-09 07:15 PM
15
cve
cve

CVE-2023-21427

Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user...

6.5CVSS

6.3AI Score

0.0004EPSS

2023-02-09 07:15 PM
22
cve
cve

CVE-2023-21432

Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the...

7.8CVSS

7.6AI Score

0.0004EPSS

2023-02-09 07:15 PM
9
cve
cve

CVE-2023-21425

Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive...

5.5CVSS

5.3AI Score

0.0004EPSS

2023-02-09 07:15 PM
14
cve
cve

CVE-2023-21424

Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator...

5.1CVSS

4.1AI Score

0.0004EPSS

2023-02-09 07:15 PM
18
cve
cve

CVE-2023-21421

Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM...

7.8CVSS

7.5AI Score

0.0004EPSS

2023-02-09 07:15 PM
14
cve
cve

CVE-2023-21446

Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of...

6.2CVSS

5.3AI Score

0.0004EPSS

2023-02-09 07:15 PM
19
cve
cve

CVE-2023-21445

Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit...

7.8CVSS

7.3AI Score

0.001EPSS

2023-02-09 07:15 PM
18
cve
cve

CVE-2023-21451

A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory...

7.8CVSS

7.4AI Score

0.0004EPSS

2023-02-09 07:15 PM
21
cve
cve

CVE-2023-21420

Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code...

7.8CVSS

8AI Score

0.0004EPSS

2023-02-09 07:15 PM
16
cve
cve

CVE-2023-21448

Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png...

5.7CVSS

4.1AI Score

0.0004EPSS

2023-02-09 07:15 PM
18
Total number of security vulnerabilities1011