Show filters
80 Total Results
Displaying 31-40 of 80
Sort by:
Attacker Value
Unknown

CVE-2020-26146

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
Attacker Value
Unknown

CVE-2020-26144

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
Attacker Value
Unknown

CVE-2020-24384

Disclosure Date: November 10, 2020 (last updated November 28, 2024)
A10 Networks ACOS and aGalaxy management Graphical User Interfaces (GUIs) have an unauthenticated Remote Code Execution (RCE) vulnerability that could be used to compromise affected ACOS systems. ACOS versions 3.2.x (including and after 3.2.2), 4.x, and 5.1.x are affected. aGalaxy versions 3.0.x, 3.2.x, and 5.0.x are affected.
Attacker Value
Unknown

CVE-2017-18681

Disclosure Date: April 07, 2020 (last updated February 21, 2025)
An issue was discovered on Samsung Galaxy S5 mobile devices with software through 2016-12-20 (Qualcomm AP chipsets). There are multiple buffer overflows in the bootloader. The Samsung ID is SVE-2016-7930 (March 2017).
Attacker Value
Unknown

CVE-2015-7890

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.
Attacker Value
Unknown

CVE-2018-16270

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.
Attacker Value
Unknown

CVE-2018-16272

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
Attacker Value
Unknown

CVE-2018-16271

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
Attacker Value
Unknown

CVE-2013-4764

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
Attacker Value
Unknown

CVE-2013-4763

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.