|
195621
|
5.9 |
MEDIUM
Network
|
samsung
|
internet
|
Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.
|
CWE-287
Improper Authentication
|
CVE-2021-25466
|
2024-11-21 14:55 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195622
|
7.0 |
HIGH
Local
|
samsung
|
themes
|
An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack.
|
CWE-20
Improper Input Validation
|
CVE-2021-25465
|
2024-11-21 14:55 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195623
|
5.5 |
MEDIUM
Local
|
samsung
|
capture
|
An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak.
|
NVD-CWE-noinfo
|
CVE-2021-25464
|
2024-11-21 14:55 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195624
|
3.3 |
LOW
Local
|
samsung
|
penup
|
Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.
|
NVD-CWE-Other
|
CVE-2021-25463
|
2024-11-21 14:55 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195625
|
5.5 |
MEDIUM
Local
|
google
|
android
|
NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-25462
|
2024-11-21 14:55 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195626
|
7.8 |
HIGH
Local
|
google
|
android
|
An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25461
|
2024-11-21 14:55 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195627
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
|
NVD-CWE-Other
|
CVE-2021-25460
|
2024-11-21 14:55 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195628
|
5.5 |
MEDIUM
Local
|
google
|
android
|
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
|
NVD-CWE-Other
|
CVE-2021-25459
|
2024-11-21 14:55 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195629
|
5.5 |
MEDIUM
Local
|
google
|
android
|
NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-25458
|
2024-11-21 14:55 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195630
|
3.3 |
LOW
Local
|
google
|
android
|
An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.
|
CWE-20
Improper Input Validation
|
CVE-2021-25457
|
2024-11-21 14:55 |
2021-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|