Samsung
Samsung Mobile: vulnerabilidades y CVE
Samsung Mobile tiene 28 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses0
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-10751 | Media (5.3) | 8.6% | — | 29 may 2018 | A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for… |
| CVE-2018-9143 | Crítica (9.8) | 2.3% | — | 30 mar 2018 | On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged process, aka SVE-2017-10991. |
| CVE-2018-9142 | Alta (7) | 0.79% | — | 30 mar 2018 | On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation of a package signature and package name, aka SVE-2017-10932. |
| CVE-2018-9141 | Alta (7.8) | 2.4% | — | 30 mar 2018 | On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a crafted resolution, aka SVE-2017-11105. |
| CVE-2018-9140 | Media (6.1) | 0.64% | — | 30 mar 2018 | On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747. |
| CVE-2018-9139 | Crítica (9.8) | 2.5% | — | 30 mar 2018 | On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privileged process via a large frame size, aka SVE-2017-11165. |
| CVE-2018-5210 | Alta (8.1) | 1.8% | — | 4 ene 2018 | On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a brute-force attack to discover unlock… |
| CVE-2017-18020 | Alta (8.4) | 0.42% | — | 4 ene 2018 | On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs data to memory. The… |
| CVE-2015-7896 | Media (6.5) | 7.0% | — | 24 ago 2017 | LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file. |
| CVE-2015-7891 | Alta (7) | 0.67% | — | 2 ago 2017 | Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory errors by leveraging definition of g2d_lock… |
| CVE-2015-7898 | Media (5.5) | 0.84% | — | 27 jun 2017 | Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). |
| CVE-2015-7895 | Media (5.5) | 1.1% | — | 27 jun 2017 | Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). |
| CVE-2017-7978 | Alta (7.5) | 1.1% | — | 19 abr 2017 | Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot. The Samsung ID is SVE-2017-8290. |
| CVE-2017-5538 | Crítica (9.8) | 2.9% | — | 23 mar 2017 | The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers to have unspecified impact via unknown… |
| CVE-2016-4547 | Alta (7.5) | 1.1% | — | 13 feb 2017 | Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C. |
| CVE-2016-4546 | Media (5.5) | 0.27% | — | 13 feb 2017 | Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a service call. |
| CVE-2016-4038 | Alta (7.8) | 0.35% | — | 1 feb 2017 | Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/msm/camera_v2/sensor/msm_sensor.c in Samsung devices with Android KK(4.4) or L and an APQ8084,… |
| CVE-2016-6527 | Alta (7.8) | 1.5% | — | 18 ene 2017 | The SmartCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed… |
| CVE-2016-6526 | Alta (7.8) | 1.5% | — | 18 ene 2017 | The SpamCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed… |
| CVE-2017-5351 | Alta (7.5) | 1.4% | — | 12 ene 2017 | Samsung Note devices with KK(4.4), L(5.0/5.1), and M(6.0) software allow attackers to crash the system by creating an arbitrarily large number of active VR service threads. The Samsung ID is SVE-2016-7650. |
| CVE-2017-5350 | Alta (7.5) | 1.4% | — | 12 ene 2017 | Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allow attackers to crash systemUI by leveraging incomplete exception handling. The Samsung ID is SVE-2016-7122. |
| CVE-2017-5217 | Media (5.5) | 0.80% | — | 9 ene 2017 | Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS. The zero-permission… |
| CVE-2016-9967 | Crítica (9.8) | 1.9% | — | 16 dic 2016 | Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash the system easily resulting in a… |
| CVE-2016-9966 | Crítica (9.8) | 1.9% | — | 16 dic 2016 | Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash the system easily resulting in a… |
| CVE-2016-9965 | Crítica (9.8) | 1.9% | — | 16 dic 2016 | Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash the system easily resulting in a… |
| CVE-2016-9567 | Media (5.5) | 0.94% | — | 23 nov 2016 | The mDNIe system service on Samsung Mobile S7 devices with M(6.0) software does not properly restrict setmDNIeScreenCurtain API calls, enabling attackers to control a device's screen. This can be exploited via a crafted… |
| CVE-2016-9277 | Alta (7.5) | 1.4% | — | 11 nov 2016 | Integer overflow in SystemUI in KK(4.4) and L(5.0/5.1) on Samsung Note devices allows attackers to cause a denial of service (UI restart) via vectors involving APIs and an activity that computes an out-of-bounds array… |
| CVE-2016-7160 | Alta (7.5) | 1.1% | — | 3 nov 2016 | A vulnerability on Samsung Mobile M(6.0) devices exists because external access to SystemUI activities is not properly restricted, leading to a SystemUI crash and device restart, aka SVE-2016-6248. |