Total
220 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-34586 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 3.3 LOW |
Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy. | |||||
CVE-2024-34585 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 7.8 HIGH |
Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. | |||||
CVE-2024-34583 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 3.3 LOW |
Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier. | |||||
CVE-2024-20901 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 7.8 HIGH |
Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory. | |||||
CVE-2024-20899 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 5.5 MEDIUM |
Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | |||||
CVE-2024-20900 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 3.3 LOW |
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication. | |||||
CVE-2024-20898 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 5.5 MEDIUM |
Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | |||||
CVE-2024-20897 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 5.5 MEDIUM |
Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | |||||
CVE-2024-20896 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 5.5 MEDIUM |
Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | |||||
CVE-2024-20895 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 5.5 MEDIUM |
Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features. | |||||
CVE-2024-20894 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 4.3 MEDIUM |
Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability. | |||||
CVE-2024-20893 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 7.8 HIGH |
Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption. | |||||
CVE-2024-20892 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 7.8 HIGH |
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability. | |||||
CVE-2024-20891 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 7.8 HIGH |
Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. | |||||
CVE-2024-20890 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 8.8 HIGH |
Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior. | |||||
CVE-2024-20889 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 4.3 MEDIUM |
Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices. | |||||
CVE-2024-20888 | 1 Samsung | 1 Android | 2024-07-05 | N/A | 7.8 HIGH |
Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability. | |||||
CVE-2024-34590 | 1 Samsung | 1 Android | 2024-07-03 | N/A | 4.3 MEDIUM |
Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability. | |||||
CVE-2024-34595 | 1 Samsung | 1 Android | 2024-07-02 | N/A | 7.8 HIGH |
Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. | |||||
CVE-2024-34594 | 1 Samsung | 1 Android | 2024-07-02 | N/A | 5.5 MEDIUM |
Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address. |