CVE-2023-21512
https://notcve.org/view.php?id=CVE-2023-21512
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=06 • CWE-269: Improper Privilege Management CWE-276: Incorrect Default Permissions •
CVE-2023-21518
https://notcve.org/view.php?id=CVE-2023-21518
Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity. • https://security.samsungmobile.com/serviceWeb.smsb?year=2023&month=06 • CWE-284: Improper Access Control •
CVE-2023-21517
https://notcve.org/view.php?id=CVE-2023-21517
Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execute arbitrary code. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=06 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-787: Out-of-bounds Write •
CVE-2023-21513
https://notcve.org/view.php?id=CVE-2023-21513
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition. • https://security.samsungmobile.com/securityUpdate.smsb?year=2023&month=06 • CWE-269: Improper Privilege Management •
CVE-2023-31114
https://notcve.org/view.php?id=CVE-2023-31114
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause unintended querying of the SIM status via a crafted application. • https://semiconductor.samsung.com/support/quality-support/product-security-updates • CWE-669: Incorrect Resource Transfer Between Spheres •