Samsung Android 13.0 SMR-JAN-2023-R1

CPE Details

Samsung Android 13.0 SMR-JAN-2023-R1
13.0
2023-02-17 14:41 +00:00
2023-02-17 17:57 +00:00

Alerte pour un CPE

Stay informed of any changes for a specific CPE.
Alert management

CPE Name: cpe:2.3:o:samsung:android:13.0:smr-jan-2023-r1:*:*:*:*:*:*

Informations

Vendor

samsung

Product

android

Version

13.0

Update

smr-jan-2023-r1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2024-20820 2024-02-06 02:23 +00:00 Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.
7.1
HIGH
CVE-2024-20819 2024-02-06 02:23 +00:00 Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
7.8
HIGH
CVE-2024-20818 2024-02-06 02:23 +00:00 Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
7.8
HIGH
CVE-2024-20817 2024-02-06 02:23 +00:00 Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
7.8
HIGH
CVE-2024-20816 2024-02-06 02:23 +00:00 Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
8
HIGH
CVE-2024-20815 2024-02-06 02:23 +00:00 Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
8
HIGH
CVE-2024-20814 2024-02-06 02:23 +00:00 Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.
5.5
MEDIUM
CVE-2024-20813 2024-02-06 02:23 +00:00 Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.
8.4
HIGH
CVE-2024-20812 2024-02-06 02:23 +00:00 Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.
8.4
HIGH
CVE-2024-20811 2024-02-06 02:23 +00:00 Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.
5.1
MEDIUM
CVE-2024-20810 2024-02-06 02:23 +00:00 Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.
3.3
LOW
CVE-2024-20806 2024-01-04 01:10 +00:00 Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.
6.2
MEDIUM
CVE-2024-20805 2024-01-04 01:10 +00:00 Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
5.5
MEDIUM
CVE-2024-20804 2024-01-04 01:10 +00:00 Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
5.5
MEDIUM
CVE-2024-20803 2024-01-04 01:10 +00:00 Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
6.8
MEDIUM
CVE-2023-42563 2023-12-05 02:49 +00:00 Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
7.8
HIGH
CVE-2023-42570 2023-12-05 02:44 +00:00 Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.
5.9
MEDIUM
CVE-2023-42569 2023-12-05 02:44 +00:00 Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.
4
MEDIUM
CVE-2023-42568 2023-12-05 02:44 +00:00 Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
7.3
HIGH
CVE-2023-42566 2023-12-05 02:44 +00:00 Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-42565 2023-12-05 02:44 +00:00 Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.
7.3
HIGH
CVE-2023-42564 2023-12-05 02:44 +00:00 Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
6.6
MEDIUM
CVE-2023-42562 2023-12-05 02:44 +00:00 Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
7.8
HIGH
CVE-2023-42561 2023-12-05 02:44 +00:00 Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.
7.1
HIGH
CVE-2023-42560 2023-12-05 02:44 +00:00 Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-42559 2023-12-05 02:44 +00:00 Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.
5.2
MEDIUM
CVE-2023-42558 2023-12-05 02:44 +00:00 Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.
7.8
HIGH
CVE-2023-42557 2023-12-05 02:44 +00:00 Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.
6.7
MEDIUM
CVE-2023-42556 2023-12-05 02:44 +00:00 Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.
5.5
MEDIUM
CVE-2023-42538 2023-11-07 07:49 +00:00 An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
7.8
HIGH
CVE-2023-42537 2023-11-07 07:49 +00:00 An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
8.4
HIGH
CVE-2023-42536 2023-11-07 07:49 +00:00 An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
8.4
HIGH
CVE-2023-42535 2023-11-07 07:49 +00:00 Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.
8.4
HIGH
CVE-2023-42534 2023-11-07 07:49 +00:00 Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.
6.3
MEDIUM
CVE-2023-42533 2023-11-07 07:49 +00:00 Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.
6.8
MEDIUM
CVE-2023-42532 2023-11-07 07:49 +00:00 Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.
7.5
HIGH
CVE-2023-42531 2023-11-07 07:49 +00:00 Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.
7.1
HIGH
CVE-2023-42530 2023-11-07 07:49 +00:00 Improper access control vulnerability in SecSettings prior to SMR Nov-2023 Release 1 allows attackers to enable Wi-Fi and Wi-Fi Direct without User Interaction.
7.5
HIGH
CVE-2023-42529 2023-11-07 07:49 +00:00 Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-42528 2023-11-07 07:49 +00:00 Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-42527 2023-11-07 07:49 +00:00 Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.
5.6
MEDIUM
CVE-2023-30739 2023-11-07 07:45 +00:00 Arbitrary File Descriptor Write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-30733 2023-10-04 03:02 +00:00 Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attackers to perform code execution.
7.8
HIGH
CVE-2023-30732 2023-10-04 03:02 +00:00 Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.
5.5
MEDIUM
CVE-2023-30731 2023-10-04 03:02 +00:00 Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.
5.7
MEDIUM
CVE-2023-30727 2023-10-04 03:02 +00:00 Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi and connect arbitrary Wi-Fi without User Interaction.
7.5
HIGH
CVE-2023-30692 2023-10-04 03:02 +00:00 Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
8.5
HIGH
CVE-2023-30690 2023-10-04 03:01 +00:00 Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
8.5
HIGH
CVE-2023-30721 2023-09-06 03:12 +00:00 Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.
4.4
MEDIUM
CVE-2023-30720 2023-09-06 03:12 +00:00 PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.
5.5
MEDIUM
CVE-2023-30719 2023-09-06 03:12 +00:00 Exposure of Sensitive Information vulnerability in InboundSmsHandler prior to SMR Sep-2023 Release 1 allows local attackers to access certain message data.
4
MEDIUM
CVE-2023-30718 2023-09-06 03:12 +00:00 Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.
4
MEDIUM
CVE-2023-30717 2023-09-06 03:12 +00:00 Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to get unresettable identifiers.
4
MEDIUM
CVE-2023-30716 2023-09-06 03:12 +00:00 Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to trigger certain commands.
5.5
MEDIUM
CVE-2023-30715 2023-09-06 03:12 +00:00 Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.
4
MEDIUM
CVE-2023-30714 2023-09-06 03:12 +00:00 Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.
4.6
MEDIUM
CVE-2023-30713 2023-09-06 03:11 +00:00 Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.
6.2
MEDIUM
CVE-2023-30712 2023-09-06 03:11 +00:00 Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.
7.8
HIGH
CVE-2023-30711 2023-09-06 03:11 +00:00 Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
4
MEDIUM
CVE-2023-30710 2023-09-06 03:11 +00:00 Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.
8.5
HIGH
CVE-2023-30709 2023-09-06 03:11 +00:00 Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.
7.9
HIGH
CVE-2023-30708 2023-09-06 03:11 +00:00 Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.
7.5
HIGH
CVE-2023-30707 2023-09-06 03:11 +00:00 Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege.
7.1
HIGH
CVE-2023-30706 2023-09-06 03:11 +00:00 Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read arbitrary file with system privilege.
7.5
HIGH
CVE-2023-30701 2023-08-10 01:18 +00:00 PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.
5.5
MEDIUM
CVE-2023-30700 2023-08-10 01:18 +00:00 PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.
5.3
MEDIUM
CVE-2023-30699 2023-08-10 01:18 +00:00 Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.
9.8
CRITICAL
CVE-2023-30698 2023-08-10 01:18 +00:00 Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.
5.5
MEDIUM
CVE-2023-30697 2023-08-10 01:18 +00:00 An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
7.8
HIGH
CVE-2023-30696 2023-08-10 01:18 +00:00 An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
7.8
HIGH
CVE-2023-30694 2023-08-10 01:18 +00:00 Out-of-bounds Write in IpcTxPcscTransmitApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-30693 2023-08-10 01:18 +00:00 Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-30691 2023-08-10 01:18 +00:00 Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.
8.4
HIGH
CVE-2023-30689 2023-08-10 01:18 +00:00 Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-30688 2023-08-10 01:18 +00:00 Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-30687 2023-08-10 01:18 +00:00 Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-30686 2023-08-10 01:18 +00:00 Out-of-bounds Write in ReqDataRaw of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-30685 2023-08-10 01:18 +00:00 Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
4.3
MEDIUM
CVE-2023-30684 2023-08-10 01:18 +00:00 Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.
4.3
MEDIUM
CVE-2023-30683 2023-08-10 01:18 +00:00 Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.
4.3
MEDIUM
CVE-2023-30682 2023-08-10 01:18 +00:00 Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.
4.3
MEDIUM
CVE-2023-30681 2023-08-10 01:18 +00:00 An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
7.8
HIGH
CVE-2023-30680 2023-08-10 01:18 +00:00 Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.
8.4
HIGH
CVE-2023-30679 2023-08-10 01:18 +00:00 Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-30654 2023-08-10 01:17 +00:00 Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to update fake location.
6.7
MEDIUM
CVE-2023-30671 2023-07-06 02:51 +00:00 Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.
6.3
MEDIUM
CVE-2023-30670 2023-07-06 02:51 +00:00 Out-of-bounds Write in BuildIpcFactoryDeviceTestEvent of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-30669 2023-07-06 02:51 +00:00 Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-30668 2023-07-06 02:51 +00:00 Out-of-bounds Write in BuildOemSecureSimLockResponse of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
7.8
HIGH
CVE-2023-30667 2023-07-06 02:51 +00:00 Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.
5.1
MEDIUM
CVE-2023-30666 2023-07-06 02:51 +00:00 Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.
7.8
HIGH
CVE-2023-30665 2023-07-06 02:51 +00:00 Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.
4.4
MEDIUM
CVE-2023-30664 2023-07-06 02:51 +00:00 Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
8.5
HIGH
CVE-2023-30663 2023-07-06 02:51 +00:00 Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.
7.8
HIGH
CVE-2023-30662 2023-07-06 02:51 +00:00 Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
6.2
MEDIUM
CVE-2023-30661 2023-07-06 02:51 +00:00 Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
6.2
MEDIUM
CVE-2023-30660 2023-07-06 02:51 +00:00 Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
6.2
MEDIUM
CVE-2023-30659 2023-07-06 02:51 +00:00 Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
7.8
HIGH
CVE-2023-30658 2023-07-06 02:51 +00:00 Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
8.5
HIGH
CVE-2023-30657 2023-07-06 02:51 +00:00 Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
7.8
HIGH
CVE-2023-30656 2023-07-06 02:51 +00:00 Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.
8.5
HIGH
CVE-2023-30655 2023-07-06 02:51 +00:00 Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
8.5
HIGH
CVE-2023-30653 2023-07-06 02:50 +00:00 Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-30652 2023-07-06 02:50 +00:00 Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-30651 2023-07-06 02:50 +00:00 Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-30650 2023-07-06 02:50 +00:00 Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-30649 2023-07-06 02:50 +00:00 Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-30648 2023-07-06 02:50 +00:00 Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.
5.5
MEDIUM
CVE-2023-30647 2023-07-06 02:50 +00:00 Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-30646 2023-07-06 02:50 +00:00 Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-30645 2023-07-06 02:50 +00:00 Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-30644 2023-07-06 02:50 +00:00 Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
7.8
HIGH
CVE-2023-30643 2023-07-06 02:50 +00:00 Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications.
7.7
HIGH
CVE-2023-30642 2023-07-06 02:50 +00:00 Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.
6.2
MEDIUM
CVE-2023-30641 2023-07-06 02:50 +00:00 Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.
4.3
MEDIUM
CVE-2023-30640 2023-07-06 02:44 +00:00 Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.
4.3
MEDIUM
CVE-2023-21512 2023-06-27 22:00 +00:00 Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.
3.3
LOW
CVE-2023-21513 2023-06-27 22:00 +00:00 Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
6.8
MEDIUM
CVE-2023-21484 2023-05-03 22:00 +00:00 Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.
7.8
HIGH
CVE-2023-21485 2023-05-03 22:00 +00:00 Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
5.3
MEDIUM
CVE-2023-21486 2023-05-03 22:00 +00:00 Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
5.3
MEDIUM
CVE-2023-21487 2023-05-03 22:00 +00:00 Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.
5.1
MEDIUM
CVE-2023-21488 2023-05-03 22:00 +00:00 Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.
7.8
HIGH
CVE-2023-21489 2023-05-03 22:00 +00:00 Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.
7.1
HIGH
CVE-2023-21490 2023-05-03 22:00 +00:00 Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.
7.1
HIGH
CVE-2023-21491 2023-05-03 22:00 +00:00 Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.
8.5
HIGH
CVE-2023-21492 2023-05-03 22:00 +00:00 Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
4.4
MEDIUM
CVE-2023-21493 2023-05-03 22:00 +00:00 Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.
6.8
MEDIUM
CVE-2023-21494 2023-05-03 22:00 +00:00 Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
9.8
CRITICAL
CVE-2023-21495 2023-05-03 22:00 +00:00 Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
5.5
MEDIUM
CVE-2023-21496 2023-05-03 22:00 +00:00 Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.
6.1
MEDIUM
CVE-2023-21497 2023-05-03 22:00 +00:00 Use of externally-controlled format string vulnerability in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the memory address.
7.8
HIGH
CVE-2023-21498 2023-05-03 22:00 +00:00 Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.
7.8
HIGH
CVE-2023-21499 2023-05-03 22:00 +00:00 Out-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.
8.2
HIGH
CVE-2023-21500 2023-05-03 22:00 +00:00 Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
6
MEDIUM
CVE-2023-21501 2023-05-03 22:00 +00:00 Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.
8.2
HIGH
CVE-2023-21502 2023-05-03 22:00 +00:00 Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands.
7.8
HIGH
CVE-2023-21503 2023-05-03 22:00 +00:00 Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
9.8
CRITICAL
CVE-2023-21504 2023-05-03 22:00 +00:00 Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
9.8
CRITICAL
CVE-2023-21452 2023-03-15 23:00 +00:00 Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
3.3
LOW
CVE-2023-21453 2023-03-15 23:00 +00:00 Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
6
MEDIUM
CVE-2023-21454 2023-03-15 23:00 +00:00 Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.
2.4
LOW
CVE-2023-21456 2023-03-15 23:00 +00:00 Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
9
CRITICAL
CVE-2023-21457 2023-03-15 23:00 +00:00 Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.
8.1
HIGH
CVE-2023-21458 2023-03-15 23:00 +00:00 Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
6.2
MEDIUM
CVE-2023-21459 2023-03-15 23:00 +00:00 Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.
9.8
CRITICAL
CVE-2023-21460 2023-03-15 23:00 +00:00 Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
4.4
MEDIUM
CVE-2023-21461 2023-03-15 23:00 +00:00 Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
5.5
MEDIUM
Click on the button to the left (OFF), to authorize the inscription of cookie improving the functionalities of the site. Click on the button to the left (Accept all), to unauthorize the inscription of cookie improving the functionalities of the site.