Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.9% | — | Samsung Galaxy S6 Firmware | 21/3/2019 | 17/6/2026 | Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to overwrite kernel memory due to improper validation of the ring buffer read pointer. The Samsung ID is SVE-2018-12029. | |
| Modificada | Media (6.3) | 0.95% | — | Samsung Galaxy S6 Firmware | 17/12/2018 | 17/6/2026 | Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi) chip to cause the device driver to perform invalid memory accesses. The… | |
| Modificada | Media (6.3) | 0.95% | — | Samsung Galaxy S6 Firmware | 17/12/2018 | 17/6/2026 | Buffer overflow in dhd_bus_flow_ring_flush_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 allow an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device driver to perform invalid memory accesses. The Samsung ID is SVE-2018-11785. | |
| Modificada | Media (6.3) | 0.95% | — | Samsung Galaxy S6 Firmware | 17/12/2018 | 17/6/2026 | Buffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device driver to perform invalid memory accesses. The… | |
| Modificada | Media (4.3) | 0.94% | — | Samsung Galaxy S6 Firmware | 17/12/2018 | 17/6/2026 | A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device to reboot. The Samsung ID is SVE-2018-11783. | |
| Modificada | Media (6.3) | 0.96% | — | Samsung Galaxy S6 Firmware | 17/12/2018 | 17/6/2026 | Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause invalid accesses to operating system memory due to improper validation… | |
| Modificada | Media (4.6) | 0.43% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 FirmwareSamsung Galaxy S4 Mini FirmwareSamsung Galaxy S4 Mini LTE Firmware+1 | 13/4/2017 | 17/6/2026 | Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices do not block AT+USBDEBUG and AT+WIFIVALUE, which allows attackers to modify… | |
| Modificada | Media (6.8) | 0.52% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 FirmwareSamsung Galaxy S4 Mini FirmwareSamsung Galaxy S4 Mini LTE Firmware+1 | 13/4/2017 | 17/6/2026 | Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices allow attackers to send AT commands by plugging the device into a Linux… | |
| Modificada | Media (6.8) | 0.51% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 FirmwareSamsung Galaxy S4 Mini FirmwareSamsung Galaxy S4 Mini LTE Firmware+1 | 13/4/2017 | 17/6/2026 | Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2… | |
| Modificada | Baja (3.3) | 0.40% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 Firmware | 13/4/2017 | 17/6/2026 | secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the… | |
| Modificada | Crítica (9.8) | 1.5% | — | Samsung Galaxy S6 Firmware | 13/4/2017 | 17/6/2026 | Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081. | |
| Modificada | Baja (3.3) | 0.42% | — | Samsung Galaxy S6 Firmware | 13/4/2017 | 17/6/2026 | Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages, aka SVE-2015-5081. | |
| Modificada | Media (5.5) | 0.36% | — | Samsung Galaxy S6 FirmwareSamsung Galaxy Note 3 Firmware | 13/4/2017 | 17/6/2026 | The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to trigger a NULL pointer dereference via a "GET HTTP/1.1" request, aka SVE-2016-5036. |