Show filters
420 Total Results
Displaying 131-140 of 420
Sort by:
Attacker Value
Unknown

CVE-2024-34611

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.
Attacker Value
Unknown

CVE-2024-34610

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.
Attacker Value
Unknown

CVE-2024-34609

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34608

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34607

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34606

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34605

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34604

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Attacker Value
Unknown

CVE-2024-34723

Disclosure Date: July 09, 2024 (last updated December 18, 2024)
In onTransact of ParcelableListBinder.java , there is a possible way to steal mAllowlistToken to launch an app from background due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Attacker Value
Unknown

CVE-2024-34722

Disclosure Date: July 09, 2024 (last updated December 18, 2024)
In smp_proc_rand of smp_act.cc, there is a possible authentication bypass during legacy BLE pairing due to incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.