CVE-2018-9141
- EPSS 0.76%
- Veröffentlicht 30.03.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:03
On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a crafted resolution, aka SVE-2017-11105.
CVE-2018-9140
- EPSS 0.36%
- Veröffentlicht 30.03.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:03
On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.
- EPSS 1.35%
- Veröffentlicht 30.03.2018 08:29:00
- Zuletzt bearbeitet 21.11.2024 04:15:03
On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privileged process via a large frame size, aka SVE-2017-11165.
CVE-2018-5210
- EPSS 1.36%
- Veröffentlicht 04.01.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 04:08:20
On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a brute-force attack to discover unlock information (PIN, password, or pa...
CVE-2017-18020
- EPSS 0.05%
- Veröffentlicht 04.01.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:11
On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs data to memory. The Samsung ID is SVE-2017-10598.
CVE-2015-7896
- EPSS 7.16%
- Veröffentlicht 24.08.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.
- EPSS 0.17%
- Veröffentlicht 02.08.2017 19:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory errors by leveraging definition of g2d_lock and g2d_unlock lock macros as n...
CVE-2015-7895
- EPSS 0.29%
- Veröffentlicht 27.06.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2015-7898
- EPSS 0.16%
- Veröffentlicht 27.06.2017 20:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2017-7978
- EPSS 0.31%
- Veröffentlicht 19.04.2017 22:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot. The Samsung ID is SVE-2017-8290.