Loading HuntDB...

Vulnerabilities

CVE-2024-34602

LOW

Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

Published Jul 08, 2024

CVE-2024-34601

MEDIUM

Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore.

Published Jul 02, 2024

CVE-2024-34600

MEDIUM

Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy image files to external storage.

Published Jul 02, 2024

CVE-2024-34599

MEDIUM

Improper input validation in Tips prior to version 6.2.9.4 in Android 14 allows local attacker to send broadcast with Tips' privilege.

Published Jul 02, 2024

CVE-2024-34597

MEDIUM

Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-34596

MEDIUM

Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.

Published Jul 02, 2024

CVE-2024-34595

HIGH

Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Published Jul 02, 2024

CVE-2024-34594

MEDIUM

Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.

Published Jul 02, 2024

CVE-2024-34593

HIGH

Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-34592

MEDIUM

Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-34591

MEDIUM

Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-34590

MEDIUM

Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-34589

MEDIUM

Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-34588

MEDIUM

Improper input validation혻in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-34587

HIGH

Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-34586

MEDIUM

Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.

Published Jul 02, 2024

CVE-2024-34585

HIGH

Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Published Jul 02, 2024

CVE-2024-34583

MEDIUM

Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.

Published Jul 02, 2024

CVE-2024-20901

MEDIUM

Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.

Published Jul 02, 2024

CVE-2024-20900

MEDIUM

Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.

Published Jul 02, 2024

CVE-2024-20899

MEDIUM

Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

Published Jul 02, 2024

CVE-2024-20898

MEDIUM

Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

Published Jul 02, 2024

CVE-2024-20897

MEDIUM

Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

Published Jul 02, 2024

CVE-2024-20896

MEDIUM

Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

Published Jul 02, 2024

CVE-2024-20895

HIGH

Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.

Published Jul 02, 2024

CVE-2024-20894

MEDIUM

Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-20893

MEDIUM

Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.

Published Jul 02, 2024

CVE-2024-20892

MEDIUM

Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-20891

HIGH

Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

Published Jul 02, 2024

CVE-2024-20890

MEDIUM

Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.

Published Jul 02, 2024

CVE-2024-20889

MEDIUM

Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.

Published Jul 02, 2024

CVE-2024-20888

HIGH

Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.

Published Jul 02, 2024

CVE-2024-20887

MEDIUM

Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory.

Published Jun 04, 2024

CVE-2024-20886

MEDIUM

Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory.

Published Jun 04, 2024

CVE-2024-20885

MEDIUM

Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.

Published Jun 04, 2024

CVE-2024-20884

MEDIUM

Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.

Published Jun 04, 2024

CVE-2024-20883

MEDIUM

Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.

Published Jun 04, 2024

CVE-2024-20882

MEDIUM

Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.

Published Jun 04, 2024

CVE-2024-20881

MEDIUM

Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local privileged attackers lead to potential arbitrary code execution.

Published Jun 04, 2024

CVE-2024-20880

MEDIUM

Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.

Published Jun 04, 2024

CVE-2024-20879

MEDIUM

Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.

Published Jun 04, 2024

CVE-2024-20878

HIGH

Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.

Published Jun 04, 2024

CVE-2024-20877

HIGH

Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.

Published Jun 04, 2024

CVE-2024-20876

MEDIUM

Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.

Published Jun 04, 2024

CVE-2024-20875

MEDIUM

Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files.

Published Jun 04, 2024

CVE-2024-20874

HIGH

Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities.

Published Jun 04, 2024

CVE-2024-20873

MEDIUM

Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

Published Jun 04, 2024

CVE-2024-20855

LOW

Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.

Published May 07, 2024

CVE-2024-20872

MEDIUM

Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.

Published May 07, 2024

CVE-2024-20871

MEDIUM

Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.

Published May 07, 2024