|
197041
|
5.5 |
MEDIUM
Local
|
samsung
|
health
|
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
|
CWE-863
Incorrect Authorization
|
CVE-2021-25506
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197042
|
7.8 |
HIGH
Local
|
samsung
|
samsung_pass
|
Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.
|
CWE-287
Improper Authentication
|
CVE-2021-25505
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197043
|
4.0 |
MEDIUM
Local
|
samsung
|
group_sharing
|
Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.
|
NVD-CWE-Other
|
CVE-2021-25504
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197044
|
6.7 |
MEDIUM
Local
|
google
|
android
|
Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.
|
CWE-20
Improper Input Validation
|
CVE-2021-25503
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197045
|
5.5 |
MEDIUM
Local
|
google
|
android
|
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2021-25502
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197046
|
3.3 |
LOW
Local
|
google
|
android
|
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.
|
NVD-CWE-Other
|
CVE-2021-25501
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197047
|
4.4 |
MEDIUM
Local
|
google
|
android
|
A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25500
|
2024-11-21 14:55 |
2021-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197048
|
4.3 |
MEDIUM
Network
|
fortinet
|
fortimanager
|
An improper access control vulnerability [CWE-284] in FortiManager versions 6.4.4 and 6.4.5 may allow an authenticated attacker with a restricted user profile to modify the VPN tunnel status of other…
|
NVD-CWE-Other
|
CVE-2021-26107
|
2024-11-21 14:55 |
2021-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197049
|
6.5 |
MEDIUM
Network
|
publify_project
|
publify
|
In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even when the admin does not allow. This happens due to front-end restriction only.
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2021-25973
|
2024-11-21 14:55 |
2021-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197050
|
6.1 |
MEDIUM
Network
|
youphptube
|
youphptube
|
AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoName parameter which allows a remote attacker to steal administrators' session c…
|
CWE-79
Cross-site Scripting
|
CVE-2021-25878
|
2024-11-21 14:55 |
2021-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|