CVE Feed

    Dashboard / CVE

    8.6
    High

    CVE-2023-43534

    Last Modified: 11 Aug 2025

    Memory corruption while validating the TID to Link Mapping action request frame, when a station connects to an access point.

    Published: 6 Feb 2024
    7.5
    High

    CVE-2023-43533

    Last Modified: 11 Aug 2025

    Transient DOS in WLAN Firmware when the length of received beacon is less than length of ieee802.11 beacon frame.

    Published: 6 Feb 2024
    8.4
    High

    CVE-2023-43532

    Last Modified: 17 Jun 2025

    Memory corruption while reading ACPI config through the user mode app.

    Published: 6 Feb 2024
    7.5
    High

    CVE-2023-43523

    Last Modified: 17 Jun 2025

    Transient DOS while processing 11AZ RTT management action frame received through OTA.

    Published: 6 Feb 2024
    7.5
    High

    CVE-2023-43522

    Last Modified: 11 Aug 2025

    Transient DOS while key unwrapping process, when the given encrypted key is empty or NULL.

    Published: 6 Feb 2024
    8.6
    High

    CVE-2023-43520

    Last Modified: 11 Aug 2025

    Memory corruption when AP includes TID to link mapping IE in the beacons and STA is parsing the beacon TID to link mapping IE.

    Published: 6 Feb 2024
    7.3
    High

    CVE-2023-43519

    Last Modified: 11 Aug 2025

    Memory corruption in video while parsing the Videoinfo, when the size of atom is greater than the videoinfo size.

    Published: 6 Feb 2024
    7.3
    High

    CVE-2023-43518

    Last Modified: 11 Aug 2025

    Memory corruption in video while parsing invalid mp2 clip.

    Published: 6 Feb 2024
    8.4
    High

    CVE-2023-43517

    Last Modified: 15 May 2025

    Memory corruption in Automotive Multimedia due to improper access control in HAB.

    Published: 6 Feb 2024
    7.8
    High

    CVE-2023-43516

    Last Modified: 15 May 2025

    Memory corruption when malformed message payload is received from firmware.

    Published: 6 Feb 2024
    7.8
    High

    CVE-2023-43513

    Last Modified: 11 Aug 2025

    Memory corruption while processing the event ring, the context read pointer is untrusted to HLOS and when it is passed with arbitrary values, may point to address in the middle of ring element.

    Published: 6 Feb 2024
    6.7
    Medium

    CVE-2023-33077

    Last Modified: 11 Aug 2025

    Memory corruption in HLOS while converting from authorization token to HIDL vector.

    Published: 6 Feb 2024
    5.9
    Medium

    CVE-2023-33076

    Last Modified: 17 Jun 2025

    Memory corruption in Core when updating rollback version for TA and OTA feature is enabled.

    Published: 6 Feb 2024
    9.3
    Critical

    CVE-2023-33072

    Last Modified: 11 Aug 2025

    Memory corruption in Core while processing control functions.

    Published: 6 Feb 2024
    6.7
    Medium

    CVE-2023-33069

    Last Modified: 11 Aug 2025

    Memory corruption in Audio while processing the calibration data returned from ACDB loader.

    Published: 6 Feb 2024
    6.7
    Medium

    CVE-2023-33068

    Last Modified: 11 Aug 2025

    Memory corruption in Audio while processing IIR config data from AFE calibration block.

    Published: 6 Feb 2024
    6.7
    Medium

    CVE-2023-33067

    Last Modified: 11 Aug 2025

    Memory corruption in Audio while calling START command on host voice PCM multiple times for the same RX or TX tap points.

    Published: 6 Feb 2024
    6.1
    Medium

    CVE-2023-33065

    Last Modified: 11 Aug 2025

    Information disclosure in Audio while accessing AVCS services from ADSP payload.

    Published: 6 Feb 2024
    5.5
    Medium

    CVE-2023-33064

    Last Modified: 11 Aug 2025

    Transient DOS in Audio when invoking callback function of ASM driver.

    Published: 6 Feb 2024
    7.1
    High

    CVE-2023-33060

    Last Modified: 21 Nov 2024

    Transient DOS in Core when DDR memory check is called while DDR is not initialized.

    Published: 6 Feb 2024
    8.2
    High

    CVE-2023-33058

    Last Modified: 21 Nov 2024

    Information disclosure in Modem while processing SIB5.

    Published: 6 Feb 2024
    7.5
    High

    CVE-2023-33057

    Last Modified: 11 Aug 2025

    Transient DOS in Multi-Mode Call Processor while processing UE policy container.

    Published: 6 Feb 2024
    7.5
    High

    CVE-2023-33049

    Last Modified: 11 Aug 2025

    Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.

    Published: 6 Feb 2024
    7.8
    High

    CVE-2023-33046

    Last Modified: 11 Aug 2025

    Memory corruption in Trusted Execution Environment while deinitializing an object used for license validation.

    Published: 6 Feb 2024
    7.5
    High

    CVE-2024-23304

    Last Modified: 4 Jun 2025

    Cybozu KUNAI for Android 3.0.20 to 3.0.21 allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition by performing certain operations.

    Published: 6 Feb 2024
    4.7
    Medium

    CVE-2024-24808

    Last Modified: 9 May 2025

    pyLoad is an open-source Download Manager written in pure Python. There is an open redirect vulnerability due to incorrect validation of input values when redirecting users after login. pyLoad is validating URLs via the `get_redirect_url` function when redirecting users at login. This vulnerability has been patched with commit fe94451.

    Published: 6 Feb 2024
    2.4
    Low

    CVE-2024-20828

    Last Modified: 21 Nov 2024

    Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.

    Published: 6 Feb 2024
    4.6
    Medium

    CVE-2024-20827

    Last Modified: 21 Nov 2024

    Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.

    Published: 6 Feb 2024
    5.5
    Medium

    CVE-2024-20826

    Last Modified: 21 Nov 2024

    Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implicit intent.

    Published: 6 Feb 2024
    5.5
    Medium

    CVE-2024-20825

    Last Modified: 15 May 2025

    Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

    Published: 6 Feb 2024
    5.5
    Medium

    CVE-2024-20824

    Last Modified: 21 Nov 2024

    Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

    Published: 6 Feb 2024
    5.5
    Medium

    CVE-2024-20823

    Last Modified: 21 Nov 2024

    Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

    Published: 6 Feb 2024
    5.5
    Medium

    CVE-2024-20822

    Last Modified: 24 Apr 2025

    Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

    Published: 6 Feb 2024
    4.4
    Medium

    CVE-2024-20820

    Last Modified: 21 Nov 2024

    Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.

    Published: 6 Feb 2024
    6.6
    Medium

    CVE-2024-20819

    Last Modified: 17 Jun 2025

    Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

    Published: 6 Feb 2024
    6.6
    Medium

    CVE-2024-20818

    Last Modified: 17 Jun 2025

    Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

    Published: 6 Feb 2024
    6.6
    Medium

    CVE-2024-20817

    Last Modified: 8 May 2025

    Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

    Published: 6 Feb 2024
    8
    High

    CVE-2024-20816

    Last Modified: 21 Nov 2024

    Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

    Published: 6 Feb 2024
    8
    High

    CVE-2024-20815

    Last Modified: 21 Nov 2024

    Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

    Published: 6 Feb 2024
    4
    Medium

    CVE-2024-20814

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.

    Published: 6 Feb 2024
    8.4
    High

    CVE-2024-20813

    Last Modified: 15 May 2025

    Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

    Published: 6 Feb 2024
    8.4
    High

    CVE-2024-20812

    Last Modified: 15 May 2025

    Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

    Published: 6 Feb 2024
    5.1
    Medium

    CVE-2024-20811

    Last Modified: 21 Nov 2024

    Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.

    Published: 6 Feb 2024
    3.3
    Low

    CVE-2024-20810

    Last Modified: 24 Apr 2025

    Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2023-6234

    Last Modified: 21 Nov 2024

    Buffer overflow in CPCA Color LUT Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2023-6233

    Last Modified: 17 Jun 2025

    Buffer overflow in SLP attribute request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2023-6232

    Last Modified: 17 Jun 2025

    Buffer overflow in the Address Book username process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2023-6231

    Last Modified: 17 Jun 2025

    Buffer overflow in WSD probe request process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2023-6230

    Last Modified: 17 Jun 2025

    Buffer overflow in the Address Book password process in authentication of Mobile Device Function of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

    Published: 6 Feb 2024
    9.8
    Critical

    CVE-2023-6229

    Last Modified: 17 Jun 2025

    Buffer overflow in CPCA PDL Resource Download process of Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code.*: Satera LBP670C Series/Satera MF750C Series firmware v03.07 and earlier sold in Japan. Color imageCLASS LBP674C/Color imageCLASS X LBP1333C/Color imageCLASS MF750C Series/Color imageCLASS X MF1333C Series firmware v03.07 and earlier sold in US. i-SENSYS LBP673Cdw/C1333P/i-SENSYS MF750C Series/C1333i Series firmware v03.07 and earlier sold in Europe.

    Published: 6 Feb 2024