Filtered by vendor Samsung
Subscribe
Total
656 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-3927 | 1 Samsung | 2 Sth-eth-250, Sth-eth-250 Firmware | 2022-04-19 | 4.3 MEDIUM | 5.9 MEDIUM |
An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. When hubCore crashes, Google Breakpad is used to record minidumps, which are sent over an insecure HTTPS connection to the backtrace.io service, leading to the exposure of sensitive data. An attacker can impersonate the remote backtrace.io server in order to trigger this vulnerability. | |||||
CVE-2022-28779 | 1 Samsung | 1 Android Usb Driver Windows Installer | 2022-04-19 | 4.6 MEDIUM | 7.8 HIGH |
Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code. | |||||
CVE-2022-27838 | 1 Samsung | 1 Factorycamera | 2022-04-19 | 7.2 HIGH | 7.8 HIGH |
Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege. | |||||
CVE-2022-27843 | 1 Samsung | 1 Kies | 2022-04-19 | 4.4 MEDIUM | 7.8 HIGH |
DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code. | |||||
CVE-2022-27842 | 1 Samsung | 1 Smart Switch Pc | 2022-04-19 | 4.4 MEDIUM | 7.8 HIGH |
DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code. | |||||
CVE-2022-28776 | 1 Samsung | 1 Galaxy Store | 2022-04-19 | 4.6 MEDIUM | 7.8 HIGH |
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions. | |||||
CVE-2022-28778 | 1 Samsung | 1 Samsung Security Supporter | 2022-04-19 | 2.1 LOW | 3.3 LOW |
Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0 allows attacker to set the arbitrary folder as Secret Folder without Samsung Security Supporter permission | |||||
CVE-2022-28777 | 1 Samsung | 1 Members | 2022-04-19 | 2.1 LOW | 3.3 LOW |
Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute call function without CALL_PHONE permission. | |||||
CVE-2022-28541 | 1 Samsung | 1 Update | 2022-04-18 | 4.6 MEDIUM | 7.8 HIGH |
Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission. | |||||
CVE-2022-27834 | 2 Google, Samsung | 4 Android, Exynos 2100, Exynos 980 and 1 more | 2022-04-18 | 4.4 MEDIUM | 7.0 HIGH |
Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions. | |||||
CVE-2022-27833 | 2 Google, Samsung | 4 Android, Exynos 2100, Exynos 980 and 1 more | 2022-04-18 | 4.6 MEDIUM | 7.8 HIGH |
Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow. | |||||
CVE-2022-25154 | 1 Samsung | 2 T5, T5 Firmware | 2022-04-13 | 4.4 MEDIUM | 7.3 HIGH |
A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows 7, 10, or 11 to exploit this vulnerability.) | |||||
CVE-2022-25830 | 1 Samsung | 1 Galaxy Watch 3 Plugin | 2022-03-18 | 2.1 LOW | 3.3 LOW |
Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log | |||||
CVE-2022-25829 | 1 Samsung | 1 Watch Active2 Plugin | 2022-03-18 | 2.1 LOW | 3.3 LOW |
Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information of connected WiFiAp in the log | |||||
CVE-2022-25828 | 1 Samsung | 1 Watch Active Plugin | 2022-03-18 | 2.1 LOW | 3.3 LOW |
Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information of connected WiFiAp in the log | |||||
CVE-2022-25827 | 1 Samsung | 1 Galaxy Watch Plugin | 2022-03-18 | 2.1 LOW | 3.3 LOW |
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information of connected WiFiAp in the log | |||||
CVE-2022-25826 | 1 Samsung | 1 Galaxy Watch 3 Plugin | 2022-03-18 | 2.1 LOW | 3.3 LOW |
Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of connected WiFiAp in the log | |||||
CVE-2022-25824 | 1 Samsung | 1 Bixby Touch | 2022-03-18 | 2.1 LOW | 3.3 LOW |
Improper access control vulnerability in BixbyTouch prior to version 2.2.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview. | |||||
CVE-2022-25823 | 1 Samsung | 1 Galaxy Watch Plugin | 2022-03-18 | 2.1 LOW | 3.3 LOW |
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log. | |||||
CVE-2022-24932 | 2 Google, Samsung | 2 Android, Cloud | 2022-03-16 | 2.1 LOW | 4.6 MEDIUM |
Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard. |