Search Results (36206 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-30703 1 Samsung 1 Members 2024-11-21 3.3 Low
Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.
CVE-2023-30701 1 Samsung 1 Android 2024-11-21 4.7 Medium
PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.
CVE-2023-30700 1 Samsung 1 Android 2024-11-21 5.3 Medium
PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.
CVE-2023-30698 1 Samsung 1 Android 2024-11-21 5.5 Medium
Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.
CVE-2023-30692 1 Samsung 1 Android 2024-11-21 8.5 High
Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
CVE-2023-30691 1 Samsung 2 Android, Samsung Mobile Devices 2024-11-21 8.4 High
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.
CVE-2023-30685 1 Samsung 1 Android 2024-11-21 4.3 Medium
Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
CVE-2023-30684 1 Samsung 1 Android 2024-11-21 4.3 Medium
Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.
CVE-2023-30683 1 Samsung 1 Android 2024-11-21 4.3 Medium
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.
CVE-2023-30682 1 Samsung 1 Android 2024-11-21 4.3 Medium
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.
CVE-2023-30679 1 Samsung 1 Android 2024-11-21 7.8 High
Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.
CVE-2023-30677 1 Samsung 1 Pass 2024-11-21 6.1 Medium
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.
CVE-2023-30676 1 Samsung 1 Pass 2024-11-21 4.6 Medium
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass.
CVE-2023-30672 1 Samsung 1 Smart Switch Pc 2024-11-21 6.8 Medium
Improper privilege management vulnerability in Samsung Smart Switch for Windows Installer prior to version 4.3.23043_3 allows attackers to cause permanent DoS via directory junction.
CVE-2023-30662 1 Samsung 1 Android 2024-11-21 6.2 Medium
Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
CVE-2023-30661 1 Samsung 1 Android 2024-11-21 6.2 Medium
Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
CVE-2023-30660 1 Samsung 1 Android 2024-11-21 6.2 Medium
Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
CVE-2023-30641 1 Samsung 1 Android 2024-11-21 4.3 Medium
Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.
CVE-2023-30633 1 Insyde 1 Insydeh2o 2024-11-21 5.3 Medium
An issue was discovered in TrEEConfigDriver in Insyde InsydeH2O with kernel 5.0 through 5.5. It can report false TPM PCR values, and thus mask malware activity. Devices use Platform Configuration Registers (PCRs) to record information about device and software configuration to ensure that the boot process is secure. (For example, Windows uses these PCR measurements to determine device health.) A vulnerable device can masquerade as a healthy device by extending arbitrary values into Platform Configuration Register (PCR) banks. This requires physical access to a target victim's device, or compromise of user credentials for a device. This issue is similar to CVE-2021-42299 (on Surface Pro devices).
CVE-2023-30437 1 Ibm 1 Security Guardium 2024-11-21 5.3 Medium
IBM Security Guardium 11.3, 11.4, and 11.5 could allow an unauthorized user to enumerate usernames by sending a specially crafted HTTP request. IBM X-Force ID: 252293.