|
196301
|
3.3 |
LOW
Local
|
samsung
|
pay
|
Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.
|
NVD-CWE-Other
|
CVE-2021-25527
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196302
|
5.5 |
MEDIUM
Local
|
samsung
|
blockchain_wallet
|
Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.
|
NVD-CWE-Other
|
CVE-2021-25526
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196303
|
6.5 |
MEDIUM
Adjacent
|
samsung
|
pay
|
Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2021-25525
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196304
|
3.3 |
LOW
Local
|
samsung
|
contacts
|
Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-25524
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196305
|
3.3 |
LOW
Local
|
samsung
|
dialer
|
Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-25523
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196306
|
3.3 |
LOW
Local
|
samsung
|
smart_capture
|
Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-25522
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196307
|
3.3 |
LOW
Local
|
samsung
|
internet
|
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2021-25521
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196308
|
6.1 |
MEDIUM
Network
|
samsung
|
internet
|
Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25520
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196309
|
3.3 |
LOW
Local
|
google
|
android
|
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.
|
CWE-862
Missing Authorization
|
CVE-2021-25519
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196310
|
6.7 |
MEDIUM
Local
|
google
|
android
|
An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25518
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|