Show filters
80 Total Results
Displaying 71-80 of 80
Sort by:
Attacker Value
Unknown

CVE-2016-2566

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.
0
Attacker Value
Unknown

CVE-2016-4030

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.
0
Attacker Value
Unknown

CVE-2015-7893

Disclosure Date: April 11, 2017 (last updated November 26, 2024)
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.
0
Attacker Value
Unknown

CVE-2015-0863

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
0
Attacker Value
Unknown

CVE-2015-0864

Disclosure Date: March 27, 2017 (last updated November 26, 2024)
Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
0
Attacker Value
Unknown

CVE-2015-7897

Disclosure Date: November 16, 2015 (last updated October 05, 2023)
The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image file.
0
Attacker Value
Unknown

CVE-2015-4034

Disclosure Date: July 06, 2015 (last updated October 05, 2023)
The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitrary files via a crafted Parcelable object in a serialized MethodSpec object.
0
Attacker Value
Unknown

CVE-2014-5547

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Mahjong Galaxy Space Lite (aka air.com.permadi.mahjongIris) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2012-6422

Disclosure Date: December 18, 2012 (last updated October 05, 2023)
The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memory and gain privileges via a crafted application, as demonstrated by ExynosAbuse.
0
Attacker Value
Unknown

CVE-2012-2980

Disclosure Date: August 21, 2012 (last updated October 04, 2023)
The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages.
0