Show filters
1,625 Total Results
Displaying 481-490 of 1,625
Sort by:
Attacker Value
Unknown

CVE-2022-33706

Disclosure Date: July 12, 2022 (last updated October 07, 2023)
Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access the pictures using S Pen air gesture.
Attacker Value
Unknown

CVE-2022-34754

Disclosure Date: July 12, 2022 (last updated October 07, 2023)
A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: Acti9 PowerTag Link C (A9XELC10-A) (V1.7.5 and prior), Acti9 PowerTag Link C (A9XELC10-B) (V2.12.0 and prior)
Attacker Value
Unknown

CVE-2022-32960

Disclosure Date: July 12, 2022 (last updated October 07, 2023)
HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for card number. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system data or terminate service.
Attacker Value
Unknown

CVE-2022-32961

Disclosure Date: July 12, 2022 (last updated October 07, 2023)
HICOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for token information. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system data or terminate service.
Attacker Value
Unknown

CVE-2022-32962

Disclosure Date: July 12, 2022 (last updated October 07, 2023)
HiCOS’ client-side citizen certificate component has a double free vulnerability. An unauthenticated physical attacker can exploit this vulnerability to corrupt memory and execute arbitrary code, manipulate system data or terminate service.
Attacker Value
Unknown

CVE-2022-32959

Disclosure Date: July 12, 2022 (last updated October 07, 2023)
HiCOS’ client-side citizen digital certificate component has a stack-based buffer overflow vulnerability when reading IC card due to insufficient parameter length validation for OS information. An unauthenticated physical attacker can exploit this vulnerability to execute arbitrary code, manipulate system data or terminate service.
Attacker Value
Unknown

CVE-2022-2347

Disclosure Date: July 07, 2022 (last updated October 08, 2023)
There exists an unchecked length field in UBoot. The U-Boot DFU implementation does not bound the length field in USB DFU download setup packets, and it does not verify that the transfer direction corresponds to the specified command. Consequently, if a physical attacker crafts a USB DFU download setup packet with a `wLength` greater than 4096 bytes, they can write beyond the heap-allocated request buffer.
Attacker Value
Unknown

CVE-2022-1955

Disclosure Date: June 30, 2022 (last updated October 07, 2023)
Session 1.13.0 allows an attacker with physical access to the victim's device to bypass the application's password/pin lock to access user data. This is possible due to lack of adequate security controls to prevent dynamic code manipulation.
Attacker Value
Unknown

CVE-2022-1747

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
The authentication mechanism used by voters to activate a voting session on the tested version of Dominion Voting Systems ImageCast X is susceptible to forgery. An attacker could leverage this vulnerability to print an arbitrary number of ballots without authorization.
Attacker Value
Unknown

CVE-2022-1746

Disclosure Date: June 24, 2022 (last updated October 07, 2023)
The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker could leverage this vulnerability to gain access to sensitive information and perform privileged actions, potentially affecting other election equipment.