Samsung Members

CPE Details

Samsung Members
-
2021-07-09
11h51 +00:00
2021-07-09
14h11 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:samsung:members:-:*:*:*:*:*:*:*

Informations

Vendor

samsung

Product

members

Version

-

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-30703 2023-08-10 01h18 +00:00 Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.
4.3
Medium
CVE-2022-30748 2022-06-07 16h21 +00:00 Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch arbitrary activity.
5.5
Medium
CVE-2022-28777 2022-04-11 17h37 +00:00 Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute call function without CALL_PHONE permission.
4.3
Medium
CVE-2021-25439 2021-07-08 11h47 +00:00 Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.
3.3
Low
CVE-2021-25438 2021-07-08 11h47 +00:00 Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview.
7.8
High
CVE-2021-25374 2021-04-09 15h38 +00:00 An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.
8.6
High
CVE-2021-25343 2021-03-04 20h03 +00:00 Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider.
4
Medium
CVE-2021-25342 2021-03-04 20h03 +00:00 Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.
4
Medium