Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Total 1324 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-30677 1 Samsung 1 Pass 2023-11-07 N/A 4.6 MEDIUM
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.
CVE-2023-30699 1 Samsung 1 Android 2023-11-07 N/A 9.8 CRITICAL
Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.
CVE-2023-30709 1 Samsung 1 Android 2023-11-07 N/A 6.7 MEDIUM
Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.
CVE-2023-30689 1 Samsung 1 Android 2023-11-07 N/A 7.8 HIGH
Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVE-2023-30692 1 Samsung 1 Android 2023-11-07 N/A 7.8 HIGH
Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
CVE-2023-30647 1 Samsung 1 Android 2023-11-07 N/A 7.8 HIGH
Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
CVE-2023-30713 1 Samsung 1 Android 2023-11-07 N/A 5.5 MEDIUM
Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.
CVE-2023-30688 1 Samsung 1 Android 2023-11-07 N/A 7.8 HIGH
Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
CVE-2023-30653 1 Samsung 1 Android 2023-11-07 N/A 7.8 HIGH
Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
CVE-2023-30648 1 Samsung 1 Android 2023-11-07 N/A 5.5 MEDIUM
Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.
CVE-2023-30711 1 Samsung 1 Android 2023-11-07 N/A 3.3 LOW
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
CVE-2023-30696 1 Samsung 1 Android 2023-11-07 N/A 7.8 HIGH
An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
CVE-2023-30666 1 Samsung 1 Android 2023-11-07 N/A 7.8 HIGH
Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.
CVE-2023-30700 1 Samsung 1 Android 2023-11-07 N/A 3.3 LOW
PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.
CVE-2023-30641 1 Samsung 1 Android 2023-11-07 N/A 4.3 MEDIUM
Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.
CVE-2023-30702 1 Samsung 8 Galaxy Book2 Go, Galaxy Book2 Go Firmware, Galaxy Book2 Pro 360 and 5 more 2023-11-07 N/A 7.8 HIGH
Stack overflow vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.
CVE-2023-30645 1 Samsung 1 Android 2023-11-07 N/A 7.8 HIGH
Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
CVE-2023-30669 1 Samsung 1 Android 2023-11-07 N/A 7.8 HIGH
Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
CVE-2023-30698 1 Samsung 1 Android 2023-11-07 N/A 5.5 MEDIUM
Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.
CVE-2023-30704 1 Samsung 1 Internet 2023-11-07 N/A 4.6 MEDIUM
Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.