|
197001
|
3.3 |
LOW
Local
|
samsung
|
dialer
|
Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-25523
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197002
|
3.3 |
LOW
Local
|
samsung
|
smart_capture
|
Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission.
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2021-25522
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197003
|
3.3 |
LOW
Local
|
samsung
|
internet
|
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2021-25521
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197004
|
6.1 |
MEDIUM
Network
|
samsung
|
internet
|
Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.
|
CWE-79
Cross-site Scripting
|
CVE-2021-25520
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197005
|
3.3 |
LOW
Local
|
google
|
android
|
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.
|
CWE-862
Missing Authorization
|
CVE-2021-25519
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197006
|
6.7 |
MEDIUM
Local
|
google
|
android
|
An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.
|
CWE-787
Out-of-bounds Write
|
CVE-2021-25518
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197007
|
7.8 |
HIGH
Local
|
google
|
android
|
An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.
|
CWE-20
Improper Input Validation
|
CVE-2021-25517
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197008
|
7.5 |
HIGH
Network
|
google
|
android
|
An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2021-25516
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197009
|
3.3 |
LOW
Local
|
google
|
android
|
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-25515
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197010
|
6.5 |
MEDIUM
Network
|
google
|
android
|
An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.
|
NVD-CWE-Other
|
CVE-2021-25514
|
2024-11-21 14:55 |
2021-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|