CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-21066

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0) (Exynos or MediaTek chipsets) software. There is a buffer overflow in a Trustlet that can cause memory corruption. The Samsung ID is SVE-2018-11599 (July 2018).

    Published: 8 Apr 2020
    5.3
    Medium

    CVE-2018-21067

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0) software. There is an information disclosure in a Trustlet because an address is logged. The Samsung ID is SVE-2018-11600 (July 2018).

    Published: 8 Apr 2020
    6.2
    Medium

    CVE-2018-21068

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.0) software. Execution of an application in a locked Secure Folder can occur without a password via a split screen. The Samsung ID is SVE-2018-11669 (July 2018).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2018-21069

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) (MediaTek chipsets) software. There is information disclosure (of kernel stack memory) in a MediaTek driver. The Samsung ID is SVE-2018-11852 (July 2018).

    Published: 8 Apr 2020
    8.4
    High

    CVE-2018-21070

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.0) devices (MSM8998 or SDM845 chipsets) software. An attacker can bypass Secure Boot and obtain root access because of a missing Bootloader integrity check. The Samsung ID is SVE-2018-11552 (May 2018).

    Published: 8 Apr 2020
    7.3
    High

    CVE-2018-21071

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0) software. Because of an unprotected intent, an attacker can read arbitrary files and emails, and take over an email account. The Samsung ID is SVE-2018-11633 (May 2018).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2018-21072

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos chipsets) software. A kernel driver allows out-of-bounds Read/Write operations and possibly arbitrary code execution. The Samsung ID is SVE-2018-11358 (May 2018).

    Published: 8 Apr 2020
    2.4
    Low

    CVE-2018-21073

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) (Galaxy S9+, Galaxy S9, Galaxy S8+, Galaxy S8, Note 8). There is access to Clipboard content in the locked state via the Edge panel. The Samsung ID is SVE-2017-10748 (May 2018).

    Published: 8 Apr 2020
    3.3
    Low

    CVE-2018-21074

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.x) (Exynos or Qualcomm chipsets) software. There is information disclosure from a Trustlet via the debug log. The Samsung ID is SVE-2017-10638 (April 2018).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2018-21047

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Factory Reset Protection (FRP) bypass via the voice assistant because Internet access begins before the Setup Wizard finishes. The Samsung ID is SVE-2018-12894 (November 2018).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2018-21075

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. The Call+ application can load classes from an unintended path, leading to Code Execution. The Samsung ID is SVE-2017-10886 (April 2018).

    Published: 8 Apr 2020
    5.5
    Medium

    CVE-2018-21076

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) (Exynos8890/8895 chipsets) software. There is information disclosure (a KASLR offset) in the Secure Driver via a modified trustlet. The Samsung ID is SVE-2017-10987 (April 2018).

    Published: 8 Apr 2020
    2.4
    Low

    CVE-2018-21046

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x) software. There is clipboard Data Exposure via the Emergency Dialer upon connecting a USB device. The Samsung ID is SVE-2018-12911 (November 2018).

    Published: 8 Apr 2020
    2.4
    Low

    CVE-2018-21077

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.x) software. There is a Clipboard content disclosure in the locked state because the keyboard may be used during an emergency call. The Samsung ID is SVE-2017-11107 (April 2018).

    Published: 8 Apr 2020
    6.2
    Medium

    CVE-2018-21045

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard access in the lockscreen state via a copy-and-paste action. The Samsung ID is SVE-2018-13381 (December 2018).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2018-21044

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) software. The sem Trustlet has a buffer overflow that leads to arbitrary TEE code execution. The Samsung IDs are SVE-2018-13230, SVE-2018-13231, SVE-2018-13232, SVE-2018-13233 (December 2018).

    Published: 8 Apr 2020
    3.3
    Low

    CVE-2018-21043

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is information disclosure about a kernel pointer in the g2d_drv driver because of logging. The Samsung ID is SVE-2018-13035 (December 2018).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2018-21042

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK with resultant privileged code execution. The Samsung ID is SVE-2018-13299 (December 2018).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2018-21078

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) software. The Contacts application allows attackers to originate video calls because SS (Supplementary Service) and USSD (Unstructured Supplementary Service Data) codes are improperly secured. The Samsung ID is SVE-2018-11469 (April 2018).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2018-21079

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), N(7.x), and O(8.0) software. There is a kernel pointer leak in the USB gadget driver. The Samsung ID is SVE-2017-10993 (March 2018).

    Published: 8 Apr 2020
    4.6
    Medium

    CVE-2018-21080

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) software. A physically proximate attacker wielding a magnet can activate NFC to bypass the lockscreen. The Samsung ID is SVE-2017-10897 (March 2018).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2018-21041

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x) software. Access to Gallery in the Secure Folder can occur without authentication. The Samsung ID is SVE-2018-13057 (December 2018).

    Published: 8 Apr 2020
    5.7
    Medium

    CVE-2020-11000

    Last Modified: 21 Nov 2024

    GreenBrowser before version 1.2 has a vulnerability where apps that rely on URL Parsing to verify that a given URL is pointing to a trust server may be susceptible to many different ways to get URL parsing and verification wrong, which allows an attacker to circumvent the access control. This problem has been patched in version 1.2.

    Published: 8 Apr 2020
    8.1
    High

    CVE-2018-21040

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is a race condition with a resultant use-after-free in the g2d driver. The Samsung ID is SVE-2018-12959 (December 2018).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2018-21039

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.0) software. With the Location permission for the compass feature in Quick Tools (aka QuickTools), an attacker can bypass the lockscreen. The Samsung ID is SVE-2018-12053 (December 2018).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2018-21038

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) software. The Secure Folder app's startup logic allows authentication bypass. The Samsung ID is SVE-2018-11628 (December 2018).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2020-11603

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. Type confusion in the MLDAP Trustlet allows arbitrary code execution. The Samsung ID is SVE-2020-16599 (April 2020).

    Published: 8 Apr 2020
    5.3
    Medium

    CVE-2020-11607

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Notification exposure occurs in Lockdown mode because of the Edge Lighting application. The Samsung ID is SVE-2020-16680 (April 2020).

    Published: 8 Apr 2020
    2.4
    Low

    CVE-2020-11606

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) software. Information about application preview (in the Secure Folder) leaks on a locked device. The Samsung ID is SVE-2019-16463 (April 2020).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2020-11605

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive information exposure from dumpstate in NFC logs. The Samsung ID is SVE-2019-16359 (April 2020).

    Published: 8 Apr 2020
    9.1
    Critical

    CVE-2020-11604

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (incorporating TEEGRIS) software. There is an Out-of-bounds read in the MLDAP Trustlet. The Samsung ID is SVE-2019-16565 (April 2020).

    Published: 8 Apr 2020
    2.4
    Low

    CVE-2020-11602

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Google Assistant leaks clipboard contents on a locked device. The Samsung ID is SVE-2019-16558 (April 2020).

    Published: 8 Apr 2020
    5.5
    Medium

    CVE-2020-11601

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is unauthorized access to applications in the Secure Folder via floating icons. The Samsung ID is SVE-2019-16195 (April 2020).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2020-11600

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) software. There is arbitrary code execution in the Fingerprint Trustlet via a memory overwrite. The Samsung IDs are SVE-2019-16587, SVE-2019-16588, SVE-2019-16589 (April 2020).

    Published: 8 Apr 2020
    9.1
    Critical

    CVE-2018-21081

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) software. In Dual Messenger, the second app can use the runtime permissions of the first app without a user's consent. The Samsung ID is SVE-2017-11018 (March 2018).

    Published: 8 Apr 2020
    8.4
    High

    CVE-2018-21082

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) software. Dex Station allows App Pinning bypass and lock-screen bypass via the "Use screen lock type to unpin" option. The Samsung ID is SVE-2017-11106 (February 2018).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2018-21083

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0), N(7.x), and O(8.0) (Exynos or Qualcomm chipsets) software. There is information disclosure (of a kernel address) via trustonic_tee. The Samsung ID is SVE-2017-11175 (February 2018).

    Published: 8 Apr 2020
    8.1
    High

    CVE-2018-21084

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.1), M(6.0), and N(7.x) software. There is a race condition with a resultant read-after-free issue in get_kek. The Samsung ID is SVE-2017-11174 (February 2018).

    Published: 8 Apr 2020
    8.1
    High

    CVE-2018-21085

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition with a resultant use-after-free in vnswap_deinit_backing_storage. The Samsung ID is SVE-2017-11176 (February 2018).

    Published: 8 Apr 2020
    8.1
    High

    CVE-2018-21086

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition with a resultant double free in vnswap_init_backing_storage. The Samsung ID is SVE-2017-11177 (February 2018).

    Published: 8 Apr 2020
    9.8
    Critical

    CVE-2018-21087

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software. There is a vnswap heap-based buffer overflow via the store function, with resultant privilege escalation. The Samsung ID is SVE-2017-10599 (January 2018).

    Published: 8 Apr 2020
    7.5
    High

    CVE-2018-21088

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can cause a reboot because InputMethodManagerService has an unprotected system service. The Samsung ID is SVE-2017-9995 (January 2018).

    Published: 8 Apr 2020
    4.3
    Medium

    CVE-2020-4291

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176334.

    Published: 8 Apr 2020
    5.4
    Medium

    CVE-2020-4290

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow any authenticated user to spoof the configuration owner of any other user which disclose sensitive information or allow for unauthorized access. IBM X-Force ID: 176333.

    Published: 8 Apr 2020
    5.3
    Medium

    CVE-2020-4289

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 176332.

    Published: 8 Apr 2020
    5.3
    Medium

    CVE-2020-4284

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could disclose sensitive information to an unauthorized user due to insufficient timeout functionality in the Web UI. IBM X-Force ID: 176207.

    Published: 8 Apr 2020
    4.3
    Medium

    CVE-2020-4282

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could allow an authenticated user to perform unauthorized actions by bypassing illegal character restrictions. X-Force ID: 176205.

    Published: 8 Apr 2020
    5.4
    Medium

    CVE-2020-4252

    Last Modified: 21 Nov 2024

    IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 175490.

    Published: 8 Apr 2020
    2.7
    Low

    CVE-2020-4164

    Last Modified: 21 Nov 2024

    IBM Security Information Queue (ISIQ) 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, and 1.0.5 could expose sensitive information from applicatino errors which could be used in further attacks against the system. IBM X-Force ID: 174400.

    Published: 8 Apr 2020
    5.4
    Medium

    CVE-2019-4746

    Last Modified: 21 Nov 2024

    IBM DOORS Next Generation (DNG/RRC) 6.0.2. 6.0.6, and 6.0.61 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 172885.

    Published: 8 Apr 2020