Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Find My Mobile MEDIUM 6.8
CVE-2023-42571

Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the Samsung Ac…

Fix: 7.3.13.4+
Fix from $1,600 2023-12-05
Account Web Software Development Kit MEDIUM 5.5
CVE-2023-42572

Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information.

Fix: 1.5.24+
Fix from $1,600 2023-12-05
Search Widget MEDIUM 5.5
CVE-2023-42573

PendingIntent hijacking vulnerability in Search Widget prior to version 3.4 in China models allows local attackers to access data.

Fix: 3.4+
Fix from $1,600 2023-12-05
Android HIGH 7.8
CVE-2023-42562

Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 …

Fix: 14.0+
Fix from $1,950 2023-12-05
Android HIGH 7.8
CVE-2023-42563

Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attac…

Fix: 14.0+
Fix from $1,950 2023-12-05
Android HIGH 7.8
CVE-2023-42566

Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.

Fix: 14.0+
Fix from $1,950 2023-12-05
Android HIGH 7.8
CVE-2023-42567

Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.

Mitigation only
Fix from $1,950 2023-12-05
Android MEDIUM 6.7
CVE-2023-42565

Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrar…

Fix: 14.0+
Fix from $1,600 2023-12-05
Android MEDIUM 5.5
CVE-2023-42564

Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.

Fix: 14.0+
Fix from $1,600 2023-12-05
Android HIGH 7.8
CVE-2023-42558

Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.

Mitigation only
Fix from $1,950 2023-12-05
Android HIGH 7.8
CVE-2023-42560

Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.

Fix: 14.0+
Fix from $1,950 2023-12-05
Android MEDIUM 6.8
CVE-2023-42561

Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.

Fix: 14.0+
Fix from $1,600 2023-12-05
Android MEDIUM 6.7
CVE-2023-42557

Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.

Fix: 14.0+
Fix from $1,600 2023-12-05
Android MEDIUM 5.5
CVE-2023-42556

Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.

Fix: 14.0+
Fix from $1,600 2023-12-05
Android MEDIUM 5.2
CVE-2023-42559

Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.

Fix: 14.0+
Fix from $1,600 2023-12-05
Exynos 9810 Firmware HIGH 7.5
CVE-2023-41111

An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 21…

Mitigation only
Fix from $1,950 2023-11-08
Exynos 9810 Firmware HIGH 7.5
CVE-2023-41112

An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 21…

Mitigation only
Fix from $1,950 2023-11-08
Pass MEDIUM 6.8
CVE-2023-42554

Improper Authentication vulnerabiity in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication.

Fix: 4.3.00.17+
Fix from $1,600 2023-11-07
Easysetup MEDIUM 5.5
CVE-2023-42555

Use of implicit intent for sensitive communication vulnerability in EasySetup prior to version 11.1.13 allows attackers to get the bluetooth address …

Fix: 11.1.13+
Fix from $1,600 2023-11-07
Email MEDIUM 5.3
CVE-2023-42553

Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.

Fix: 6.1.90.4+
Fix from $1,600 2023-11-07
Account MEDIUM 6.5
CVE-2023-42549

Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity in Samsung Account prior to version 14.5.00.7 allows …

Fix: 14.5.00.7+
Fix from $1,600 2023-11-07
Account MEDIUM 6.5
CVE-2023-42550

Use of implicit intent for sensitive communication vulnerability in startSignIn in Samsung Account prior to version 14.5.00.7 allows attackers to acc…

Fix: 14.5.00.7+
Fix from $1,600 2023-11-07
Account MEDIUM 6.5
CVE-2023-42551

Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung Account prior to version 14.5.00.7 allows attackers t…

Fix: 14.5.00.7+
Fix from $1,600 2023-11-07
Phone HIGH 7.5
CVE-2023-42545

Use of implicit intent for sensitive communication vulnerability in Phone prior to versions 12.7.20.12 in Android 11, 13.1.48, 13.5.28 in Android 12,…

Fix: 12.7.20.12 / 13.1.48+
Fix from $1,950 2023-11-07
Account MEDIUM 6.5
CVE-2023-42546

Use of implicit intent for sensitive communication vulnerability in startAgreeToDisclaimerActivity in Samsung Account prior to version 14.5.00.7 allo…

Fix: 14.5.00.7+
Fix from $1,600 2023-11-07
Account MEDIUM 6.5
CVE-2023-42547

Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity in Samsung Account prior to version 14.5.00.7 allows…

Fix: 14.5.00.7+
Fix from $1,600 2023-11-07
Account MEDIUM 6.5
CVE-2023-42548

Use of implicit intent for sensitive communication vulnerability in startMandatoryCheckActivity in Samsung Account prior to version 14.5.00.7 allows …

Fix: 14.5.00.7+
Fix from $1,600 2023-11-07
Bixby Voice HIGH 7.5
CVE-2023-42543

Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary da…

Fix: 3.3.35.12+
Fix from $1,950 2023-11-07
Quick Share MEDIUM 5.5
CVE-2023-42544

Improper access control vulnerability in Quick Share prior to 13.5.52.0 allows local attacker to access local files.

Fix: 13.5.52.0+
Fix from $1,600 2023-11-07
Android HIGH 7.8
CVE-2023-42538

An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and …

Mitigation only
Fix from $1,950 2023-11-07