Total
352 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-20896 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 5.5 MEDIUM |
Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | |||||
CVE-2024-20895 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 7.7 HIGH |
Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features. | |||||
CVE-2024-20894 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 4.3 MEDIUM |
Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability. | |||||
CVE-2024-20893 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 6.1 MEDIUM |
Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption. | |||||
CVE-2024-20892 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 6.5 MEDIUM |
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability. | |||||
CVE-2024-20891 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 7.8 HIGH |
Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. | |||||
CVE-2024-20890 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 5.3 MEDIUM |
Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior. | |||||
CVE-2024-20889 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 5.9 MEDIUM |
Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices. | |||||
CVE-2024-20888 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 7.8 HIGH |
Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability. | |||||
CVE-2024-20820 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 4.4 MEDIUM |
Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read. | |||||
CVE-2024-20819 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 6.6 MEDIUM |
Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow. | |||||
CVE-2024-20818 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 6.6 MEDIUM |
Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow. | |||||
CVE-2024-20817 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 6.6 MEDIUM |
Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow. | |||||
CVE-2024-20816 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 8.0 HIGH |
Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness. | |||||
CVE-2024-20815 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 8.0 HIGH |
Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness. | |||||
CVE-2024-20814 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 4.0 MEDIUM |
Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information. | |||||
CVE-2024-20811 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 5.1 MEDIUM |
Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer. | |||||
CVE-2024-20810 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 3.3 LOW |
Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information. | |||||
CVE-2024-20806 | 1 Samsung | 1 Android | 2024-11-21 | N/A | 6.2 MEDIUM |
Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data. | |||||
CVE-2024-20804 | 1 Samsung | 2 Android, Myfiles | 2024-11-21 | N/A | 4.0 MEDIUM |
Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file. |