Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In December 2022
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the editNameMit parameter at /goform/editFileName.
CVSS Score
7.5
EPSS Score
0.003
Published
2022-12-08
Tenda W30E V1.0.1.25(633) was discovered to contain a stack overflow via the new_account parameter at /goform/editUserName.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-12-08
Exposure of Sensitive Information vulnerability in kernel prior to SMR Dec-2022 Release 1 allows attackers to access the kernel address information via log.
CVSS Score
4.4
EPSS Score
0.0
Published
2022-12-08
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.
CVSS Score
4.0
EPSS Score
0.0
Published
2022-12-08
Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.
CVSS Score
5.7
EPSS Score
0.0
Published
2022-12-08
Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch.
CVSS Score
4.6
EPSS Score
0.001
Published
2022-12-08
Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.
CVSS Score
6.5
EPSS Score
0.002
Published
2022-12-08
Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.
CVSS Score
6.5
EPSS Score
0.005
Published
2022-12-08
Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.
CVSS Score
4.0
EPSS Score
0.0
Published
2022-12-08
Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.
CVSS Score
3.3
EPSS Score
0.0
Published
2022-12-08


Contact Us

Shodan ® - All rights reserved