Show filters
155 Total Results
Displaying 141-150 of 155
Sort by:
Attacker Value
Unknown

CVE-2016-2036

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to trigger a NULL pointer dereference via a "GET HTTP/1.1" request, aka SVE-2016-5036.
0
Attacker Value
Unknown

CVE-2016-4032

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices do not block AT+USBDEBUG and AT+WIFIVALUE, which allows attackers to modify Android settings by leveraging AT access, aka SVE-2016-5301.
0
Attacker Value
Unknown

CVE-2016-2567

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the http://should-have-been-filtered.example.com/?http://google.com URL.
0
Attacker Value
Unknown

CVE-2016-2566

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.
0
Attacker Value
Unknown

CVE-2016-4030

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.
0
Attacker Value
Unknown

CVE-2015-7893

Disclosure Date: April 11, 2017 (last updated November 26, 2024)
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.
0
Attacker Value
Unknown

CVE-2015-0863

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
0
Attacker Value
Unknown

CVE-2015-0864

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
0
Attacker Value
Unknown

CVE-2015-7897

Disclosure Date: November 16, 2015 (last updated October 05, 2023)
The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image file.
0
Attacker Value
Unknown

CVE-2015-4034

Disclosure Date: July 06, 2015 (last updated October 05, 2023)
The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitrary files via a crafted Parcelable object in a serialized MethodSpec object.
0