Vulnerabilities
Vulnerable Software
Samsung:  Security Vulnerabilities
Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.
CVSS Score
5.9
EPSS Score
0.002
Published
2022-09-09
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
CVSS Score
3.9
EPSS Score
0.003
Published
2022-09-09
Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.
CVSS Score
1.9
EPSS Score
0.001
Published
2022-09-09
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a missing sqlite3_close after sqlite3_open_v2, leading to a denial of service.
CVSS Score
7.5
EPSS Score
0.01
Published
2022-09-08
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-09-08
sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading to a denial of service.
CVSS Score
7.5
EPSS Score
0.011
Published
2022-09-05
There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new.
CVSS Score
7.5
EPSS Score
0.011
Published
2022-09-05
sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coordinates, leading to a denial of service.
CVSS Score
7.5
EPSS Score
0.011
Published
2022-09-05
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject.
CVSS Score
7.5
EPSS Score
0.011
Published
2022-09-01
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.
CVSS Score
7.5
EPSS Score
0.011
Published
2022-09-01


Contact Us

Shodan ® - All rights reserved