samsung Vulnerabilities and Affected Products
Vulnerabilities associated with Samsung Galaxy Apps.
Products
Clear product- android44 vulnerabilities
- SmartThings Hub STH-ETH-25023 vulnerabilities
- Mobile Devices13 vulnerabilities
- Samsung11 vulnerabilities
- exynos_13809 vulnerabilities
- exynos_13308 vulnerabilities
- exynos_12807 vulnerabilities
- exynos_8507 vulnerabilities
- exynos_9806 vulnerabilities
- notes5 vulnerabilities
- samsung_mobile_devices5 vulnerabilities
- exynos_22004 vulnerabilities
- exynos_980_firmware4 vulnerabilities
- magician4 vulnerabilities
- exynos_10803 vulnerabilities
- exynos_1380_firmware3 vulnerabilities
- exynos_21003 vulnerabilities
- exynos_w9203 vulnerabilities
- Galaxy S93 vulnerabilities
- Samsung Galaxy Apps3 vulnerabilities
- exynos_1280_firmware2 vulnerabilities
- exynos_1330_firmware2 vulnerabilities
- exynos_14802 vulnerabilities
- exynos_850_firmware2 vulnerabilities
- exynos_91102 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-10502HIGH | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 4.2.18.2. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of a staging mode. The issue lies in the ability to change the configuration based on the presence of a file in an user-controlled location. An attacker can leverage this vulnera… | CVSS7.8v3.0 | EPSS0.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-10500HIGH | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of push messages. The issue lies in the ability to start an activity with controlled arguments. An attacker can leverage this vulnerability to escalate privileges to resources no… CWE-284Sep 24, 2018 | CVSS7.0v3.0 | EPSS0.226% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-10499HIGH | This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of URLs. The issue lies in the lack of proper validation of user-supplied data, which can allow arbitrary JavaScript to execute. An attacker can leverage this vulnerability to… CWE-20Sep 24, 2018 | CVSS7.0v3.0 | EPSS0.321% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |