Show filters
155 Total Results
Displaying 51-60 of 155
Sort by:
Attacker Value
Unknown

CVE-2022-25823

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log.
Attacker Value
Unknown

CVE-2022-22288

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.
Attacker Value
Unknown

CVE-2021-25499

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provider of Galaxy Store.
Attacker Value
Unknown

CVE-2021-25424

Disclosure Date: June 11, 2021 (last updated February 22, 2025)
Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.
Attacker Value
Unknown

CVE-2021-25421

Disclosure Date: June 11, 2021 (last updated February 22, 2025)
Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
Attacker Value
Unknown

CVE-2021-25420

Disclosure Date: June 11, 2021 (last updated February 22, 2025)
Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi password connected to the user smartphone within log.
Attacker Value
Unknown

CVE-2020-26145

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
Attacker Value
Unknown

CVE-2020-26146

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
Attacker Value
Unknown

CVE-2020-26144

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject arbitrary network packets independent of the network configuration.
Attacker Value
Unknown

CVE-2021-26807

Disclosure Date: April 30, 2021 (last updated February 22, 2025)
GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PATH, which allows an attacker to potentially run code locally through unsigned DLL loading.