Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mtower HIGH 7.5
CVE-2022-40760

A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACUpdate function in Samsung mTower through 0.3.0 allows a trusted application t…

Fix: after 0.3.0
Fix from $1,950 2022-09-16
Mtower HIGH 7.5
CVE-2022-40761

The function tee_obj_free in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function …

Fix: after 0.3.0
Fix from $1,950 2022-09-16
Mtower HIGH 7.5
CVE-2022-40762

A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 allows a trusted application t…

Fix: after 0.3.0
Fix from $1,950 2022-09-16
Smart Switch Pc HIGH 7.8
CVE-2022-39846

DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.

Fix: 4.3.22083_3+
Fix from $1,950 2022-09-09
Smart Switch Pc HIGH 7.1
CVE-2022-39844

Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attackers to delete arbitrary directo…

Fix: 4.3.22083+
Fix from $1,950 2022-09-09
Kies HIGH 7.1
CVE-2022-39845

Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers to delete arbitrary director…

Fix: 2.6.4.22074+
Fix from $1,950 2022-09-09
Galaxy Watch Plugin MEDIUM 6.2
CVE-2022-36874

Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IM…

Fix: 2.2.11.22040751+
Fix from $1,600 2022-09-09
Galaxy Watch Plugin MEDIUM 5.5
CVE-2022-36875

Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the f…

Fix: 2.2.11.22081151+
Fix from $1,600 2022-09-09
Samsung Email HIGH 7.8
CVE-2022-36864

Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute priv…

Fix: 6.1.70.20+
Fix from $1,950 2022-09-09
Samsung Pay MEDIUM 6.5
CVE-2022-36870

Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows att…

Fix: 5.0.63 / 5.1.47+
Fix from $1,600 2022-09-09
Samsung Pay MEDIUM 6.5
CVE-2022-36871

Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to acc…

Fix: 5.0.63 / 5.1.47+
Fix from $1,600 2022-09-09
Samsung Pay MEDIUM 6.5
CVE-2022-36872

Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to ac…

Fix: 5.0.63 / 5.1.47+
Fix from $1,600 2022-09-09
Galaxy Watch Plugin MEDIUM 6.5
CVE-2022-36873

Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the c…

Fix: 2.2.11.22081151+
Fix from $1,600 2022-09-09
Contacts Provider MEDIUM 6.1
CVE-2022-36869

Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file withou…

Fix: 12.7.59+
Fix from $1,600 2022-09-09
Editor Lite MEDIUM 5.5
CVE-2022-36867

Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.

Fix: 4.0.40.14+
Fix from $1,600 2022-09-09
Tizenrt HIGH 7.5
CVE-2022-40280

An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a m…

Mitigation only
Fix from $1,950 2022-09-08
Tizenrt HIGH 7.5
CVE-2022-40281

An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SS…

Mitigation only
Fix from $1,950 2022-09-08
Mtower HIGH 7.5
CVE-2022-39828

sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading to a denial of service.

Fix: after 0.3.0
Fix from $1,950 2022-09-05
Mtower HIGH 7.5
CVE-2022-39829

There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_ne…

Fix: after 0.3.0
Fix from $1,950 2022-09-05
Mtower HIGH 7.5
CVE-2022-39830

sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coordinates, leading to a denial…

Fix: after 0.3.0
Fix from $1,950 2022-09-05
Mtower HIGH 7.5
CVE-2022-36621

Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject.

Fix: after 0.3.0
Fix from $1,950 2022-09-01
Mtower HIGH 7.5
CVE-2022-36622

Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.

Fix: after 0.3.0
Fix from $1,950 2022-09-01
Mtower HIGH 7.5
CVE-2022-38155

TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated…

Fix: after 0.3.0
Fix from $1,950 2022-08-11
Gameoptimizingservice HIGH 7.8
CVE-2022-36833

Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above…

Fix: 3.3.04.0 / 3.5.04.8+
Fix from $1,950 2022-08-05
Update HIGH 7.8
CVE-2022-36840

DLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code.

Fix: 2.2.9.50+
Fix from $1,950 2022-08-05
Charm Firmware MEDIUM 5.5
CVE-2022-36836

Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.

Fix: 1.2.3+
Fix from $1,600 2022-08-05
Samsung Email MEDIUM 5.5
CVE-2022-36837

Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.

Fix: 6.1.70.20+
Fix from $1,600 2022-08-05
Checkout MEDIUM 5.5
CVE-2022-36839

SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP information.

Fix: 5.0.53.1+
Fix from $1,600 2022-08-05
Game Launcher MEDIUM 5.0
CVE-2022-36834

Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interacti…

Fix: 6.0.07+
Fix from $1,600 2022-08-05
Charm MEDIUM 5.5
CVE-2022-33734

Sensitive information exposure in onCharacteristicChanged in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection info…

Fix: 1.2.3+
Fix from $1,600 2022-08-05