Page 37 of 2383 results (0.009 seconds)

CVSS: 8.4EPSS: 0%CPEs: 75EXPL: 0

An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write. Una validación de entrada incorrecta en get_head_crc en libsaped antes de SMR Nov-2023 Release 1 permite al atacante provocar lecturas y escrituras fuera de los límites. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=11 • CWE-125: Out-of-bounds Read CWE-787: Out-of-bounds Write •

CVSS: 8.4EPSS: 0%CPEs: 75EXPL: 0

An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write. Una validación de entrada incorrecta en saped_dec en libsaped antes de SMR Nov-2023 Release 1 permite que un atacante provoque lecturas y escrituras fuera de los límites. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=11 • CWE-125: Out-of-bounds Read CWE-787: Out-of-bounds Write •

CVSS: 7.5EPSS: 0%CPEs: 75EXPL: 0

Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information. La validación de certificado incorrecta en FotaAgent antes de SMR Nov-2023 Release 1, permite a un atacante remoto interceptar el tráfico de la red, incluida la información del Firmware. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=11 • CWE-295: Improper Certificate Validation •

CVSS: 7.1EPSS: 0%CPEs: 75EXPL: 0

Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background. Una vulnerabilidad de control de acceso inadecuado en SmsController anterior a SMR Nov-2023 Release 1, permite al atacante omitir las restricciones para iniciar actividades en segundo plano. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=11 • CWE-287: Improper Authentication •

CVSS: 7.5EPSS: 0%CPEs: 75EXPL: 0

Improper access control vulnerability in SecSettings prior to SMR Nov-2023 Release 1 allows attackers to enable Wi-Fi and Wi-Fi Direct without User Interaction. Una vulnerabilidad de control de acceso inadecuado en SecSettings anterior a SMR Nov-2023 Release 1 permite a los atacantes habilitar Wi-Fi y Wi-Fi Direct sin Interacción del Usuario. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=11 •