CWE-926

Improper Export of Android Application Components

Parent: CWE-285 - Improper Authorization

The Android application exports a component for use by other applications, but does not properly restrict which applications can launch the component or access the data it contains.

82 vulnerabilities with CWE-926
CVE-2021-25526 MEDIUM
Samsung Blockchain Wallet <1.3.02.8 - Privilege Escalation
CVSS 4.0
CVE-2021-25400 HIGH
Samsung Internet <14.0.1.20 - Privilege Escalation
CVSS 7.8
CVE-2021-25397 MEDIUM
TelephonyUI <SMR MAY-2021 Release 1 - Privilege Escalation
CVSS 6.8
CVE-2021-25391 MEDIUM
Secure Folder <SMR MAY-2021 Release 1 - Privilege Escalation
CVSS 4.0
CVE-2021-25390 MEDIUM
PhotoTable <SMR MAY-2021 Release 1 - Privilege Escalation
CVSS 4.0
CVE-2021-25388 HIGH
Knox Core <SMR MAY-2021 Release 1 - Privilege Escalation
CVSS 7.1
CVE-2021-25379 MEDIUM
Gallery <5.4.16.1 - Privilege Escalation
CVSS 4.0
Details
Vulnerabilities 82