Show filters
1,505 Total Results
Displaying 121-130 of 1,505
Sort by:
Attacker Value
Unknown

CVE-2024-34610

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.
Attacker Value
Unknown

CVE-2024-34609

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34608

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34607

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34606

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34605

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34604

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34723

Disclosure Date: July 09, 2024 (last updated December 18, 2024)
In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2024-34722

Disclosure Date: July 09, 2024 (last updated December 18, 2024)
In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2024-34721

Disclosure Date: July 09, 2024 (last updated December 18, 2024)
In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.