Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In January 2022
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
CVSS Score
4.0
EPSS Score
0.0
Published
2022-01-10
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.
CVSS Score
4.4
EPSS Score
0.001
Published
2022-01-10
Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.
CVSS Score
6.1
EPSS Score
0.0
Published
2022-01-10
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
CVSS Score
4.0
EPSS Score
0.0
Published
2022-01-10
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
CVSS Score
4.0
EPSS Score
0.0
Published
2022-01-10
CVE-2022-22265
Known exploited
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
CVSS Score
5.0
EPSS Score
0.002
Published
2022-01-10
Improper sanitization of incoming intent in Dressroom prior to SMR Jan-2022 Release 1 allows local attackers to read and write arbitrary files without permission.
CVSS Score
7.7
EPSS Score
0.0
Published
2022-01-10
Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.
CVSS Score
4.0
EPSS Score
0.0
Published
2022-01-10
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-01-10
soketi is an open-source WebSockets server. There is an unhandled case when reading POST requests which results in the server crashing if it could not read the body of a request. In the event that a POST request is sent to any endpoint of the server with an empty body, even unauthenticated with the Pusher Protocol, it will crash the server. All users that run the server are affected by this vulnerability and it's highly recommended to upgrade to the latest patch. There are no workarounds for this issue.
CVSS Score
7.5
EPSS Score
0.005
Published
2022-01-10


Contact Us

Shodan ® - All rights reserved