CVE-2024-20825
- EPSS 0.05%
- Veröffentlicht 06.02.2024 03:15:10
- Zuletzt bearbeitet 21.11.2024 08:53:13
Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
CVE-2024-20824
- EPSS 0.05%
- Veröffentlicht 06.02.2024 03:15:10
- Zuletzt bearbeitet 21.11.2024 08:53:13
Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
CVE-2024-20823
- EPSS 0.05%
- Veröffentlicht 06.02.2024 03:15:10
- Zuletzt bearbeitet 21.11.2024 08:53:13
Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
CVE-2024-20822
- EPSS 0.05%
- Veröffentlicht 06.02.2024 03:15:09
- Zuletzt bearbeitet 21.11.2024 08:53:13
Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.
CVE-2023-42580
- EPSS 0.37%
- Veröffentlicht 05.12.2023 03:15:19
- Zuletzt bearbeitet 21.11.2024 08:22:49
Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.
CVE-2023-42581
- EPSS 0.29%
- Veröffentlicht 05.12.2023 03:15:19
- Zuletzt bearbeitet 21.11.2024 08:22:50
Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.
CVE-2023-30705
- EPSS 0.05%
- Veröffentlicht 10.08.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 08:00:43
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission.
CVE-2023-21516
- EPSS 0.46%
- Veröffentlicht 26.05.2023 22:15:14
- Zuletzt bearbeitet 21.11.2024 07:42:59
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
CVE-2023-21515
- EPSS 0.24%
- Veröffentlicht 26.05.2023 22:15:14
- Zuletzt bearbeitet 21.11.2024 07:42:59
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
CVE-2023-21514
- EPSS 0.18%
- Veröffentlicht 26.05.2023 22:15:14
- Zuletzt bearbeitet 21.11.2024 07:42:59
Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.