Vulnerabilities
Vulnerable Software
Samsung:  Security Vulnerabilities
A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACUpdate with an excessive size value of chunkSize.
CVSS Score
7.5
EPSS Score
0.012
Published
2022-09-16
The function tee_obj_free in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_AllocateOperation with a disturbed heap layout, related to utee_cryp_obj_alloc.
CVSS Score
7.5
EPSS Score
0.013
Published
2022-09-16
A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_Realloc with an excessive number for the parameter len.
CVSS Score
7.5
EPSS Score
0.009
Published
2022-09-16
Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attackers to delete arbitrary directory using directory junction.
CVSS Score
5.5
EPSS Score
0.002
Published
2022-09-09
Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers to delete arbitrary directory using directory junction.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-09-09
DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.
CVSS Score
6.2
EPSS Score
0.002
Published
2022-09-09
Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.
CVSS Score
5.9
EPSS Score
0.002
Published
2022-09-09
Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.
CVSS Score
6.6
EPSS Score
0.002
Published
2022-09-09
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.
CVSS Score
1.8
EPSS Score
0.003
Published
2022-09-09
Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.
CVSS Score
2.8
EPSS Score
0.002
Published
2022-09-09


Contact Us

Shodan ® - All rights reserved