Show filters
80 Total Results
Displaying 21-30 of 80
Sort by:
Attacker Value
Unknown

CVE-2022-33709

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
Attacker Value
Unknown

CVE-2022-33708

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
Attacker Value
Unknown

CVE-2022-28793

Disclosure Date: May 03, 2022 (last updated February 23, 2025)
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
Attacker Value
Unknown

CVE-2022-28791

Disclosure Date: May 03, 2022 (last updated February 23, 2025)
Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.
Attacker Value
Unknown

CVE-2022-28776

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.
Attacker Value
Unknown

CVE-2022-28544

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.
Attacker Value
Unknown

CVE-2022-28542

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.
Attacker Value
Unknown

CVE-2022-22288

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.
Attacker Value
Unknown

CVE-2021-25499

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provider of Galaxy Store.
Attacker Value
Unknown

CVE-2021-25424

Disclosure Date: June 11, 2021 (last updated February 22, 2025)
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.