|
196221
|
5.3 |
MEDIUM
Network
|
samsung
|
email
|
An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.
|
CWE-662
Improper Synchronization
|
CVE-2021-25376
|
2024-11-21 14:54 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196222
|
6.5 |
MEDIUM
Network
|
samsung
|
email
|
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2021-25375
|
2024-11-21 14:54 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196223
|
7.5 |
HIGH
Network
|
samsung
|
members
|
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remot…
|
NVD-CWE-Other
|
CVE-2021-25374
|
2024-11-21 14:54 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196224
|
7.8 |
HIGH
Local
|
samsung
|
customization_service
|
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local a…
|
NVD-CWE-noinfo
|
CVE-2021-25373
|
2024-11-21 14:54 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196225
|
7.8 |
HIGH
Local
|
google
|
android
|
An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-25365
|
2024-11-21 14:54 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196226
|
3.3 |
LOW
Local
|
google
|
android
|
A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-25364
|
2024-11-21 14:54 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196227
|
6.1 |
MEDIUM
Local
|
google
|
android
|
An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete some local files.
|
CWE-269
Improper Privilege Management
|
CVE-2021-25363
|
2024-11-21 14:54 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196228
|
6.1 |
MEDIUM
Local
|
google
|
android
|
An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.
|
CWE-269
Improper Privilege Management
|
CVE-2021-25362
|
2024-11-21 14:54 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196229
|
8.8 |
HIGH
Local
|
google
|
android
|
An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.
|
NVD-CWE-Other
|
CVE-2021-25361
|
2024-11-21 14:54 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196230
|
9.8 |
CRITICAL
Network
|
google
|
android
|
An improper input validation vulnerability in libswmfextractor library prior to SMR APR-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25360
|
2024-11-21 14:54 |
2021-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|