Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 33% | — | Samsung Exynos Modem 5300 FirmwareSamsung Exynos Modem 5123 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 Firmware+1 | 13/3/2023 | 17/6/2026 | The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service. | |
| Modificada | Crítica (9.8) | 0.95% | — | Samsung Exynos 850 FirmwareSamsung Exynos 980 FirmwareSamsung Exynos 1080 FirmwareSamsung Exynos 1280 Firmware+5 | 10/3/2023 | 17/6/2026 | An issue was discovered in Samsung Mobile Chipset and Baseband Modem Chipset for Exynos 850, Exynos 980, Exynos 1080, Exynos 1280, Exynos 2200, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. An intra-object overflow in the 5G MM message codec can occur due to insufficient parameter validation when… | |
| Modificada | Alta (7.5) | 0.80% | — | Samsung Exynos Firmware | 8/12/2022 | 17/6/2026 | Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call. | |
| Modificada | Media (6.5) | 0.25% | — | Samsung Exynos Firmware | 8/12/2022 | 17/6/2026 | Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB. | |
| Modificada | Crítica (9.1) | 0.90% | — | Samsung Exynos Firmware | 9/11/2022 | 17/6/2026 | Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory. | |
| Modificada | Crítica (9.1) | 1.2% | — | Samsung Exynos | 31/8/2020 | 17/6/2026 | An issue was discovered on Samsung mobile devices with software through 2020-04-02 (Exynos modem chipsets). There is a heap-based buffer over-read in the Shannon baseband. The Samsung ID is SVE-2020-17239 (August 2020). | |
| Modificada | Crítica (9.8) | 1.5% | — | Samsung Exynos Smp1300 | 24/3/2020 | 17/6/2026 | An issue was discovered on Samsung mobile devices with any (before September 2019 for SMP1300 Exynos modem chipsets) software. Attackers can trigger stack corruption in the Shannon modem via a crafted RP-Originator/Destination address. The Samsung ID is SVE-2019-14858 (September 2019). | |
| Modificada | Crítica (9.8) | 1.5% | — | Samsung Exynos | 24/3/2020 | 17/6/2026 | An issue was discovered on Samsung mobile devices with any (before February 2020 for Exynos modem chipsets) software. There is a buffer overflow in baseband CP message decoding. The Samsung IDs are SVE-2019-15816 and SVE-2019-15817 (February 2020). | |
| Modificada | Alta (7.8) | 0.22% | — | Google AndroidSamsung Exynos 8895 | 4/2/2020 | 17/6/2026 | On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL2 implementation) allows arbitrary memory write operations. The Samsung ID is SVE-2019-16265. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Crítica (9.8) | 2.6% | — | Samsung Exynos Fimg2d | 30/1/2017 | 17/6/2026 | NULL pointer dereference in Samsung Exynos fimg2d driver for Android L(5.0/5.1) and M(6.0) allows attackers to have unspecified impact via unknown vectors. The Samsung ID is SVE-2016-6382. | |
| Modificada | Alta (7.5) | 2.0% | — | Samsung Exynos Fimg2d Driver | 18/1/2017 | 17/6/2026 | Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853. | |
| Modificada | Media (5.5) | 0.41% | — | Samsung Exynos Fimg2d Driver | 18/1/2017 | 17/6/2026 | The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736. |