Show filters
155 Total Results
Displaying 11-20 of 155
Sort by:
Attacker Value
Unknown

CVE-2024-20825

Disclosure Date: February 06, 2024 (last updated February 10, 2024)
Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
Attacker Value
Unknown

CVE-2024-20824

Disclosure Date: February 06, 2024 (last updated February 10, 2024)
Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
Attacker Value
Unknown

CVE-2024-20823

Disclosure Date: February 06, 2024 (last updated February 10, 2024)
Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
Attacker Value
Unknown

CVE-2024-20822

Disclosure Date: February 06, 2024 (last updated February 10, 2024)
Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
Attacker Value
Unknown

CVE-2023-42581

Disclosure Date: December 05, 2023 (last updated December 13, 2023)
Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.
Attacker Value
Unknown

CVE-2023-42580

Disclosure Date: December 05, 2023 (last updated December 13, 2023)
Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.
Attacker Value
Unknown

CVE-2023-6032

Disclosure Date: November 15, 2023 (last updated December 01, 2023)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.
Attacker Value
Unknown

CVE-2023-30738

Disclosure Date: October 04, 2023 (last updated October 09, 2023)
An improper input validation in UEFI Firmware prior to Firmware update Oct-2023 Release in Galaxy Book, Galaxy Book Pro, Galaxy Book Pro 360 and Galaxy Book Odyssey allows local attacker to execute SMM memory corruption.
Attacker Value
Unknown

CVE-2023-42812

Disclosure Date: September 22, 2023 (last updated October 08, 2023)
Galaxy is an open-source platform for FAIR data analysis. Prior to version 22.05, Galaxy is vulnerable to server-side request forgery, which allows a malicious to issue arbitrary HTTP/HTTPS requests from the application server to internal hosts and read their responses. Version 22.05 contains a patch for this issue.
Attacker Value
Unknown

CVE-2023-30705

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission.