|
256511
|
4.6 |
MEDIUM
Physics
|
samsung
|
android
|
Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.
|
NVD-CWE-noinfo
|
CVE-2024-34645
|
2024-09-6 03:02 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256512
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.
|
NVD-CWE-Other
|
CVE-2024-34646
|
2024-09-6 03:01 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256513
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.
|
NVD-CWE-noinfo
|
CVE-2024-34655
|
2024-09-6 03:00 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256514
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.
|
NVD-CWE-noinfo
|
CVE-2024-34654
|
2024-09-6 03:00 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256515
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.
|
NVD-CWE-noinfo
|
CVE-2024-34647
|
2024-09-6 03:00 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256516
|
3.3 |
LOW
Local
|
samsung
|
android
|
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34652
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256517
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34651
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256518
|
3.3 |
LOW
Local
|
samsung
|
android
|
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
|
CWE-863
Incorrect Authorization
|
CVE-2024-34650
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256519
|
2.4 |
LOW
Physics
|
samsung
|
android
|
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.
|
NVD-CWE-Other
|
CVE-2024-34649
|
2024-09-6 02:59 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256520
|
4.3 |
MEDIUM
Network
|
samsung
|
assistant
|
Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerab…
|
CWE-276
Incorrect Default Permissions
|
CVE-2024-34661
|
2024-09-6 02:57 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|