CVE-2020-15582
https://notcve.org/view.php?id=CVE-2020-15582
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 7885 chipsets) software. The Bluetooth Low Energy (BLE) component has a buffer overflow with a resultant deadlock or crash. The Samsung ID is SVE-2020-16870 (July 2020). Se detectó un problema en dispositivos móviles Samsung con versiones de software P(9.0) y Q(10.0) (chipsets Exynos 7885). El componente Bluetooth Low Energy (BLE) presenta un desbordamiento del búfer con un punto muerto o bloqueo resultante. • https://security.samsungmobile.com/securityUpdate.smsb • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2020-13831
https://notcve.org/view.php?id=CVE-2020-13831
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic Kinibi component allows arbitrary memory mapping. The Samsung ID is SVE-2019-16665 (June 2020). Se detectó un problema en los dispositivos móviles Samsung con versiones de software O(8.x) y P(9.0) (chipsets Exynos 7570). El componente Trustonic Kinibi permite una asignación de memoria arbitraria. • https://security.samsungmobile.com/securityUpdate.smsb • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2020-12747
https://notcve.org/view.php?id=CVE-2020-12747
An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos980 9630 and Exynos990 9830 chipsets) software. The Bootloader has a heap-based buffer overflow because of the mishandling of specific commands. The Samsung IDs are SVE-2020-16981, SVE-2020-16991 (May 2020). Se detectó un problema en los dispositivos móviles Samsung con versiones de software Q(10.0) (chipsets Exynos980 9630 y Exynos990 9830). El Cargador de arranque presenta un desbordamiento de búfer en la región heap de la memoria debido al manejo inapropiado de comandos específicos. • https://security.samsungmobile.com/securityUpdate.smsb • CWE-787: Out-of-bounds Write •
CVE-2020-6616
https://notcve.org/view.php?id=CVE-2020-6616
Some Broadcom chips mishandle Bluetooth random-number generation because a low-entropy Pseudo Random Number Generator (PRNG) is used in situations where a Hardware Random Number Generator (HRNG) should have been used to prevent spoofing. This affects, for example, Samsung Galaxy S8, S8+, and Note8 devices with the BCM4361 chipset. The Samsung ID is SVE-2020-16882 (May 2020). Algunos chips Broadcom manejan inapropiadamente la generación de números aleatorios de Bluetooth porque es usado un Pseudo Random Number Generator (PRNG) de baja entropía en situaciones en las que debería haberse utilizado un Hardware Random Number Generator (HRNG) para impedir la suplantación de identidad. Esto afecta, por ejemplo, a los dispositivos Samsung Galaxy S8, S8+ y Note8 con el chipset BCM4361. • http://bluetooth.lol http://seclists.org/fulldisclosure/2020/May/49 https://github.com/seemoo-lab/internalblue/blob/master/doc/rng.md https://media.ccc.de/v/DiVOC-6-finding_eastereggs_in_broadcom_s_bluetooth_random_number_generator https://security.samsungmobile.com/securityUpdate.smsb https://support.apple.com/HT211168 https://support.apple.com/kb/HT211100 https://support.apple.com/kb/HT211168 https://twitter.com/naehrdine/status/1255980443368919045 https://twitter.com/naehrdine/status/ •
CVE-2015-8546
https://notcve.org/view.php?id=CVE-2015-8546
An issue was discovered on Samsung mobile devices with software through 2015-11-12, affecting the Galaxy S6/S6 Edge, Galaxy S6 Edge+, and Galaxy Note5 with the Shannon333 chipset. There is a stack-based buffer overflow in the baseband process that is exploitable for remote code execution via a fake base station. The Samsung ID is SVE-2015-5123 (December 2015). Se detectó un problema en dispositivos móviles Samsung con versiones de software hasta el 12-11-2015, afectando a Galaxy S6/S6 Edge, Galaxy S6 Edge+ y Galaxy Note5 con el chipset Shannon333. Se presenta un desbordamiento de búfer en la región stack de la memoria en el proceso baseband que es explotable para una ejecución de código remota por medio de una estación base falsa. • https://security.samsungmobile.com/securityUpdate.smsb • CWE-787: Out-of-bounds Write •