|
197741
|
6.7 |
MEDIUM
Local
|
google
|
android
|
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
|
NVD-CWE-noinfo
|
CVE-2021-25371
|
2024-11-21 14:54 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197742
|
4.4 |
MEDIUM
Local
|
google
|
android
|
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
|
CWE-416
Use After Free
|
CVE-2021-25370
|
2024-11-21 14:54 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197743
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
|
NVD-CWE-Other
|
CVE-2021-25369
|
2024-11-21 14:54 |
2021-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197744
|
7.5 |
HIGH
Network
|
samsung
|
cloud
|
Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.
|
CWE-287
Improper Authentication
|
CVE-2021-25368
|
2024-11-21 14:54 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197745
|
5.4 |
MEDIUM
Network
|
samsung
|
notes
|
Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.
|
CWE-22
Path Traversal
|
CVE-2021-25367
|
2024-11-21 14:54 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197746
|
2.9 |
LOW
Physics
|
samsung
|
internet
|
Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.
|
NVD-CWE-Other
|
CVE-2021-25366
|
2024-11-21 14:54 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197747
|
7.8 |
HIGH
Local
|
samsung
|
notes
|
Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
|
CWE-276
Incorrect Default Permissions
|
CVE-2021-25355
|
2024-11-21 14:54 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197748
|
5.3 |
MEDIUM
Local
|
samsung
|
internet
|
Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.
|
NVD-CWE-Other
|
CVE-2021-25354
|
2024-11-21 14:54 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197749
|
7.1 |
HIGH
Local
|
samsung
|
galaxy_themes
|
Using empty PendingIntent in Galaxy Themes prior to version 5.2.00.1215 allows local attackers to read/write private file directories of Galaxy Themes application without permission via hijacking the…
|
NVD-CWE-noinfo
|
CVE-2021-25353
|
2024-11-21 14:54 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197750
|
7.8 |
HIGH
Local
|
samsung
|
bixby_voice
|
Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-25352
|
2024-11-21 14:54 |
2021-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|