Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

195 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.34%—GOG Galaxy14/7/202017/6/2026
In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious code in a Trojan horse GalaxyClientService.exe. After that, the attacker can re-start this service as an unprivileged user to escalate his/her privileges and run commands…
ModificadaAlta (7.8)1.0%—GOG Galaxy5/7/202017/6/2026
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repair operation. The issue exists because of weak file permissions and can be exploited by using opportunistic locks.
ModificadaAlta (7.8)1.3%—GOG Galaxy5/7/202017/6/2026
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or uninstalls a game because of weak file permissions and missing file integrity checks.
ModificadaCrítica (9.8)1.5%—Samsung Galaxy S5 Firmware7/4/202017/6/2026
An issue was discovered on Samsung Galaxy S5 mobile devices with software through 2016-12-20 (Qualcomm AP chipsets). There are multiple buffer overflows in the bootloader. The Samsung ID is SVE-2016-7930 (March 2017).
ModificadaMedia (5.5)1.3%💥 ExploitSamsung Galaxy S6 Edge Firmware12/2/202017/6/2026
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.
ModificadaCrítica (9.8)1.6%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+622/1/202017/6/2026
The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
ModificadaMedia (6.5)0.81%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+622/1/202017/6/2026
The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based…
ModificadaAlta (7.5)1.2%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+622/1/202017/6/2026
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction. This allows an unprivileged process to dump Bluetooth HCI packets to an arbitrary file path.
ModificadaAlta (7.5)1.4%—Samsung Galaxy Gear FirmwareSamsung Gear 2 FirmwareSamsung Gear Live FirmwareSamsung Gear S Firmware+622/1/202017/6/2026
The wnoti system service in Samsung Galaxy Gear series allows an unprivileged process to take over the internal notification message data, due to improper D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
ModificadaMedia (4.3)0.29%—Samsung Galaxy S3 FirmwareSamsung Galaxy S4 Firmware27/12/201916/6/2026
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
ModificadaMedia (4.6)0.35%—Samsung Galaxy S3 FirmwareSamsung Galaxy S4 Firmware27/12/201916/6/2026
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.
ModificadaAlta (7.8)0.75%💥 PoCGOG Galaxy21/11/201917/6/2026
An exploitable local privilege escalation vulnerability exists in the GalaxyClientService installed by GOG Galaxy. Due to Improper Access Control, an attacker can send unauthenticated local TCP packets to the service to gain SYSTEM privileges in Windows system where GOG Galaxy software is installed. All GOG Galaxy…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J7 PRO Firmware14/11/201917/6/2026
The Samsung J7 Pro Android device with a build fingerprint of samsung/j7y17lteubm/j7y17lte:8.1.0/M1AJQ/J730GMUBS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J7 PRO Firmware14/11/201917/6/2026
The Samsung J7 Pro Android device with a build fingerprint of samsung/j7y17lteub/j7y17lte:8.1.0/M1AJQ/J730GUBS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J7 Prime Firmware14/11/201917/6/2026
The Samsung j7popeltemtr Android device with a build fingerprint of samsung/j7popeltemtr/j7popeltemtr:8.1.0/M1AJQ/J727T1UVS5BSC2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J7 DUO Firmware14/11/201917/6/2026
The Samsung J7 Duo Android device with a build fingerprint of samsung/j7duolteub/j7duolte:8.0.0/R16NW/J720MUBS3ASB2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J7 NEO Firmware14/11/201917/6/2026
The Samsung J7 Neo Android device with a build fingerprint of samsung/j7velteub/j7velte:8.1.0/M1AJQ/J701MUBS6BSB4:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J7 NEO Firmware14/11/201917/6/2026
The Samsung J7 Neo Android device with a build fingerprint of samsung/j7veltedx/j7velte:8.1.0/M1AJQ/J701FXVS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J7 NEO Firmware14/11/201917/6/2026
The Samsung J7 Neo Android device with a build fingerprint of samsung/j7velteub/j7velte:8.1.0/M1AJQ/J701MUBS6BSB3:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J7 NEO Firmware14/11/201917/6/2026
The Samsung J7 Neo Android device with a build fingerprint of samsung/j7veltedx/j7velte:8.1.0/M1AJQ/J701FXXS6BSC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J6 Firmware14/11/201917/6/2026
The Samsung J6 Android device with a build fingerprint of samsung/j6ltexx/j6lte:8.0.0/R16NW/J600FNXXU3ASC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J6 Firmware14/11/201917/6/2026
The Samsung J6 Android device with a build fingerprint of samsung/j6ltexx/j6lte:8.0.0/R16NW/J600FNXXU3ASC1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J5 Firmware14/11/201917/6/2026
The Samsung J5 Android device with a build fingerprint of samsung/j5y17ltexx/j5y17lte:8.1.0/M1AJQ/J530FXXU3BRL1:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000100, versionName=7.0.1.0) that allows other pre-installed apps to perform app…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J4 Firmware14/11/201917/6/2026
The Samsung J4 Android device with a build fingerprint of samsung/j4lteub/j4lte:8.0.0/R16NW/J400MUBU2ARL4:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation…
ModificadaAlta (7.8)0.31%—Samsung Galaxy J4 Firmware14/11/201917/6/2026
The Samsung J4 Android device with a build fingerprint of samsung/j4lteub/j4lte:8.0.0/R16NW/J400MUBS2ASC2:user/release-keys contains a pre-installed app with a package name of com.samsung.android.themecenter app (versionCode=7000000, versionName=7.0.0.0) that allows other pre-installed apps to perform app installation…
Orbitaley — Vulnerabilidades