Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Android HIGH 7.8
CVE-2023-21421

Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker…

Mitigation only
Fix from $1,950 2023-02-09
Android MEDIUM 5.5
CVE-2023-21422

Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server w…

Mitigation only
Fix from $1,600 2023-02-09
Calendar MEDIUM 5.5
CVE-2022-39915

Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Androi…

Fix: 11.6.08.0 / 12.2.11.3000+
Fix from $1,600 2022-12-08
Exynos Firmware HIGH 7.5
CVE-2022-39902

Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emer…

Mitigation only
Fix from $1,950 2022-12-08
Pass MEDIUM 6.8
CVE-2022-39911

Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass.

Fix: 4.0.06.1+
Fix from $1,600 2022-12-08
Exynos Firmware MEDIUM 6.5
CVE-2022-39901

Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between U…

Mitigation only
Fix from $1,600 2022-12-08
Gear Iconx Pc Manager MEDIUM 5.5
CVE-2022-39909

Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers t…

Fix: 2.1.221019.51+
Fix from $1,600 2022-12-08
Pass CRITICAL 9.8
CVE-2022-39892

Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.

Fix: 4.0.05.1+
Fix from $2,300 2022-11-09
Billing HIGH 7.5
CVE-2022-39890

Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.

Fix: 5.0.56.0+
Fix from $1,950 2022-11-09
Editor Lite HIGH 7.5
CVE-2022-39891

Heap overflow vulnerability in parse_pce function in libsavsaudio.so in Editor Lite prior to version 4.0.41.3 allows attacker to get information.

Fix: 4.0.41.3+
Fix from $1,950 2022-11-09
Exynos Firmware CRITICAL 9.1
CVE-2022-39881

Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of…

Mitigation only
Fix from $2,300 2022-11-09
Account MEDIUM 5.5
CVE-2022-39874

Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

Fix: 13.5.01.3+
Fix from $1,600 2022-10-07
Checkout MEDIUM 5.5
CVE-2022-39878

Improper access control vulnerability in Samsung Checkout prior to version 5.0.55.3 allows attackers to access sensitive information via implicit int…

Fix: 5.0.55.3+
Fix from $1,600 2022-10-07
Group Sharing MEDIUM 5.3
CVE-2022-39877

Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(…

Fix: 13.0.6.14 / 13.0.6.15+
Fix from $1,600 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39867

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39868

Improper access control vulnerability in GedSamsungAccount.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive information …

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39869

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39870

Improper access control vulnerability in cloudNotificationManager.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39871

Improper access control vulnerability cloudNotificationManager.java in SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inf…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Dynamic Lockscreen CRITICAL 9.8
CVE-2022-39862

Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use …

Fix: 3.3.03.66+
Fix from $2,300 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39864

Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive informa…

Fix: 1.7.85.25+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39865

Improper access control vulnerability in ContentsSharingActivity.java SmartThings prior to version 1.7.89.0 allows attackers to access sensitive info…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Smartthings HIGH 7.5
CVE-2022-39866

Improper access control vulnerability in RegisteredEventMediator.kt SmartThings prior to version 1.7.89.0 allows attackers to access sensitive inform…

Fix: 1.7.89.0+
Fix from $1,950 2022-10-07
Factorycamera HIGH 7.8
CVE-2022-39858

Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamer…

Fix: 3.5.51+
Fix from $1,950 2022-10-07
Factorycamerafb MEDIUM 5.5
CVE-2022-39857

Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent…

Fix: 3.5.51+
Fix from $1,600 2022-10-07
Tizenrt HIGH 7.5
CVE-2022-40278

An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a m…

No fix yet
Fix from $1,950 2022-09-29
Tizenrt HIGH 7.5
CVE-2022-40279

An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/src/l2_packet/l2_packet_pcap.c …

No fix yet
Fix from $1,950 2022-09-29
Mtower HIGH 7.5
CVE-2022-40757

A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACComputeFinal function in Samsung mTower through 0.3.0 allows a trusted applica…

Fix: after 0.3.0
Fix from $1,950 2022-09-16
Mtower HIGH 7.5
CVE-2022-40758

A Buffer Access with Incorrect Length Value vulnerablity in the TEE_CipherUpdate function in Samsung mTower through 0.3.0 allows a trusted applicatio…

Fix: after 0.3.0
Fix from $1,950 2022-09-16
Mtower HIGH 7.5
CVE-2022-40759

A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial…

Fix: after 0.3.0
Fix from $1,950 2022-09-16