CVE-2021-25403
- EPSS 0.07%
- Published 11.06.2021 15:15:09
- Last modified 21.11.2024 05:54:55
Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.
CVE-2021-25381
- EPSS 0.04%
- Published 09.04.2021 18:15:15
- Last modified 21.11.2024 05:54:52
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
CVE-2021-25350
- EPSS 0.05%
- Published 25.03.2021 17:15:13
- Last modified 21.11.2024 05:54:48
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.
CVE-2021-25351
- EPSS 0.05%
- Published 25.03.2021 17:15:13
- Last modified 21.11.2024 05:54:49
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.