Vulnerabilities
Vulnerable Software
Samsung:  Security Vulnerabilities
Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication
CVSS Score
5.7
EPSS Score
0.001
Published
2022-01-10
A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attackers to execute privileged action by hijacking and modifying the intent.
CVSS Score
4.4
EPSS Score
0.001
Published
2022-01-10
Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.
CVSS Score
2.8
EPSS Score
0.001
Published
2022-01-10
CVE-2022-22265
Known exploited
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
CVSS Score
5.0
EPSS Score
0.002
Published
2022-01-10
Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6.04, are susceptible to denial of service via malformed routing messages.
CVSS Score
6.5
EPSS Score
0.001
Published
2022-01-10
The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.
CVSS Score
7.5
EPSS Score
0.005
Published
2021-12-20
Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.
CVSS Score
5.9
EPSS Score
0.005
Published
2021-12-08
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.
CVSS Score
4.0
EPSS Score
0.001
Published
2021-12-08
Insecure storage of sensitive information vulnerability in Smart Capture prior to version 4.8.02.10 allows attacker to access victim's captured images without permission.
CVSS Score
5.3
EPSS Score
0.001
Published
2021-12-08
Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.
CVSS Score
4.0
EPSS Score
0.001
Published
2021-12-08


Contact Us

Shodan ® - All rights reserved