Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.2) | 0.18% | — | MI 5S Plus FirmwareSony Xperia Z4 FirmwareSamsung Galaxy S6 Edge FirmwareSamsung Galaxy S4 Firmware+4 | 6/6/2019 | 17/6/2026 | Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch. | |
| Modificada | Crítica (9.8) | 5.9% | — | Samsung Galaxy S9 Firmware | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the GameServiceReceiver update mechanism. An attacker can leverage this… | |
| Modificada | Crítica (9.3) | 3.2% | — | Samsung Galaxy S9 Firmware | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security Update (SMR-JAN-2019 - SVE-2018-13467). User interaction is required to exploit this vulnerability in that the target must connect to a wireless network. The specific… | |
| Modificada | Alta (8.8) | 3.3% | — | Samsung Galaxy S9 Firmware | 3/6/2019 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security Update (SMR-JAN-2019 - SVE-2018-13467). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious… | |
| Modificada | Alta (8.8) | 1.9% | — | Samsung Galaxy S6 Firmware | 21/3/2019 | 17/6/2026 | Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to overwrite kernel memory due to improper validation of the ring buffer read pointer. The Samsung ID is SVE-2018-12029. | |
| Modificada | Media (6.3) | 0.95% | — | Samsung Galaxy S6 Firmware | 17/12/2018 | 17/6/2026 | Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi) chip to cause the device driver to perform invalid memory accesses. The… | |
| Modificada | Media (6.3) | 0.95% | — | Samsung Galaxy S6 Firmware | 17/12/2018 | 17/6/2026 | Buffer overflow in dhd_bus_flow_ring_flush_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 allow an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device driver to perform invalid memory accesses. The Samsung ID is SVE-2018-11785. | |
| Modificada | Media (6.3) | 0.95% | — | Samsung Galaxy S6 Firmware | 17/12/2018 | 17/6/2026 | Buffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device driver to perform invalid memory accesses. The… | |
| Modificada | Media (4.3) | 0.94% | — | Samsung Galaxy S6 Firmware | 17/12/2018 | 17/6/2026 | A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device to reboot. The Samsung ID is SVE-2018-11783. | |
| Modificada | Media (6.3) | 0.96% | — | Samsung Galaxy S6 Firmware | 17/12/2018 | 17/6/2026 | Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause invalid accesses to operating system memory due to improper validation… | |
| Modificada | Alta (8.8) | 2.5% | — | Samsung Galaxy S8 Firmware | 24/9/2018 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S8 G950FXXU1AQL5. User interaction is required to exploit this vulnerability in that the target must have their cellular radios enabled. The specific flaw exists within the handling of IPCP headers. The… | |
| Modificada | Crítica (9.8) | 3.9% | — | Samsung Galaxy S4 Firmware | 24/8/2017 | 17/6/2026 | The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory corruption) or gain privileges. | |
| Modificada | Alta (7.5) | 2.8% | — | Samsung Galaxy S4 Firmware | 24/8/2017 | 17/6/2026 | The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive information. | |
| Modificada | Alta (8.8) | 8.9% | 💥 Exploit | Samsung Galaxy S6 Edge Firmware | 9/8/2017 | 17/6/2026 | The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a denial of service (segmentation fault and process crash) and execute arbitrary code via a crafted JPG. | |
| Modificada | Alta (7.5) | 4.0% | — | Samsung Galaxy S6 Edge Firmware | 7/6/2017 | 17/6/2026 | Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a .. (dot dot) in the name of a file, compressed into a zipped file named cred.zip, and downloaded to /sdcard/Download. | |
| Modificada | Media (4.6) | 0.43% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 FirmwareSamsung Galaxy S4 Mini FirmwareSamsung Galaxy S4 Mini LTE Firmware+1 | 13/4/2017 | 17/6/2026 | Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices do not block AT+USBDEBUG and AT+WIFIVALUE, which allows attackers to modify… | |
| Modificada | Media (6.8) | 0.52% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 FirmwareSamsung Galaxy S4 Mini FirmwareSamsung Galaxy S4 Mini LTE Firmware+1 | 13/4/2017 | 17/6/2026 | Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices allow attackers to send AT commands by plugging the device into a Linux… | |
| Modificada | Media (6.8) | 0.51% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 FirmwareSamsung Galaxy S4 Mini FirmwareSamsung Galaxy S4 Mini LTE Firmware+1 | 13/4/2017 | 17/6/2026 | Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2… | |
| Modificada | Baja (3.3) | 0.40% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 Firmware | 13/4/2017 | 17/6/2026 | secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the… | |
| Modificada | Crítica (9.8) | 1.5% | — | Samsung Galaxy S6 Firmware | 13/4/2017 | 17/6/2026 | Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081. | |
| Modificada | Baja (3.3) | 0.42% | — | Samsung Galaxy S6 Firmware | 13/4/2017 | 17/6/2026 | Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages, aka SVE-2015-5081. | |
| Modificada | Media (5.5) | 0.36% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 Firmware | 13/4/2017 | 17/6/2026 | The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to trigger a NULL pointer dereference via a "GET HTTP/1.1" request, aka SVE-2016-5036. | |
| Modificada | Alta (8.8) | 7.4% | 💥 Exploit | Samsung Galaxy S6 | 11/4/2017 | 17/6/2026 | SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript. | |
| Modificada | Alta (7.5) | 7.0% | 💥 Exploit | Samsung Galaxy S6 | 16/11/2015 | 17/6/2026 | The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image file. | |
| Modificada | Alta (7.9) | 1.2% | — | Samsung Galaxy S5 | 6/7/2015 | 17/6/2026 | The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitrary files via a crafted Parcelable object in a serialized MethodSpec object. |