Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Total 1089 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30692 1 Samsung 1 Android 2024-11-21 N/A 8.5 HIGH
Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
CVE-2023-30691 1 Samsung 1 Android 2024-11-21 N/A 8.4 HIGH
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.
CVE-2023-30690 1 Samsung 1 Android 2024-11-21 N/A 8.5 HIGH
Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
CVE-2023-30689 1 Samsung 1 Android 2024-11-21 N/A 6.7 MEDIUM
Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVE-2023-30688 1 Samsung 1 Android 2024-11-21 N/A 6.7 MEDIUM
Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVE-2023-30687 1 Samsung 1 Android 2024-11-21 N/A 6.7 MEDIUM
Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVE-2023-30686 1 Samsung 1 Android 2024-11-21 N/A 6.7 MEDIUM
Out-of-bounds Write in ReqDataRaw of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVE-2023-30685 1 Samsung 1 Android 2024-11-21 N/A 4.3 MEDIUM
Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
CVE-2023-30684 1 Samsung 1 Android 2024-11-21 N/A 4.3 MEDIUM
Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.
CVE-2023-30683 1 Samsung 1 Android 2024-11-21 N/A 4.3 MEDIUM
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.
CVE-2023-30682 1 Samsung 1 Android 2024-11-21 N/A 4.3 MEDIUM
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.
CVE-2023-30681 1 Samsung 1 Android 2024-11-21 N/A 4.4 MEDIUM
An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
CVE-2023-30680 1 Samsung 1 Android 2024-11-21 N/A 8.4 HIGH
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.
CVE-2023-30679 1 Samsung 1 Android 2024-11-21 N/A 7.8 HIGH
Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.
CVE-2023-30678 2 Google, Samsung 2 Android, Calendar 2024-11-21 N/A 5.1 MEDIUM
Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.
CVE-2023-30677 1 Samsung 1 Pass 2024-11-21 N/A 6.1 MEDIUM
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.
CVE-2023-30676 1 Samsung 1 Pass 2024-11-21 N/A 4.6 MEDIUM
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass.
CVE-2023-30675 1 Samsung 1 Pass 2024-11-21 N/A 6.2 MEDIUM
Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed.
CVE-2023-30674 1 Samsung 1 Internet 2024-11-21 N/A 6.5 MEDIUM
Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie.
CVE-2023-30673 1 Samsung 1 Smart Switch Pc 2024-11-21 N/A 5.5 MEDIUM
Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.23052_1 allows local attackers to delete arbitrary directory using directory junction.