Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
1690 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.18% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.19% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.20% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system. | |
| Modificada | Alta (7.8) | 0.20% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.20% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.20% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.20% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code. | |
| Modificada | Alta (7.1) | 0.16% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications. | |
| Modificada | Media (5.5) | 0.14% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function. | |
| Modificada | Media (4.3) | 0.25% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data. | |
| Modificada | Baja (3.3) | 0.14% | — | Samsung Android | 6/7/2023 | 17/6/2026 | Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration. | |
| Modificada | Alta (7.8) | 0.21% | — | Samsung Searchwidget | 28/6/2023 | 17/6/2026 | Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity. | |
| Modificada | Crítica (9.8) | 1.6% | — | Samsung Exynos | 28/6/2023 | 17/6/2026 | Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execute arbitrary code. | |
| Modificada | Media (6.8) | 0.39% | — | Samsung Android | 28/6/2023 | 17/6/2026 | Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition. | |
| Modificada | Baja (3.3) | 0.22% | — | Samsung Android | 28/6/2023 | 17/6/2026 | Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission. | |
| Modificada | Crítica (9.8) | 0.62% | — | Samsung Exynos 5123 FirmwareSamsung Exynos 5300 Firmware | 7/6/2023 | 17/6/2026 | Se descubrió un problema en Shannon RCS component en Samsung Exynos Modem 5123 y 5300. Un permiso predeterminado incorrecto puede provocar una consulta no deseada de la capacidad RCS a través de una aplicación manipulada específicamente para ello. | |
| Modificada | Alta (7.5) | 0.49% | — | Samsung Exynos 5123 FirmwareSamsung Exynos 5300 Firmware | 7/6/2023 | 17/6/2026 | Se descubrió un problema en Shannon RCS component en Samsung Exynos Modem 5123 y 5300. La transferencia incorrecta de recursos entre esferas puede provocar cambios en el modo de activación de RCS a través de una aplicación manipulada específicamente para ello. | |
| Modificada | Crítica (9.1) | 0.56% | — | Samsung Exynos 5123 FirmwareSamsung Exynos 5300 Firmware | 7/6/2023 | 17/6/2026 | Se descubrió un problema en Shannon RCS component en Samsung Exynos Modem 5123 y 5300. La transferencia incorrecta de recursos entre esferas puede provocar una consulta no deseada del estado de la SIM a través de una aplicación manipulada específicamente para ello. | |
| Modificada | Crítica (9.6) | 0.55% | — | Samsung Galaxy Store | 26/5/2023 | 17/6/2026 | XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | |
| Modificada | Alta (8.8) | 0.52% | — | Samsung Galaxy Store | 26/5/2023 | 17/6/2026 | InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. | |
| Modificada | Alta (8.8) | 0.52% | — | Samsung Galaxy Store | 26/5/2023 | 17/6/2026 | Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store. |