Samsung Galaxy S4 Firmware vulnerabilities

6 known vulnerabilities affecting samsung/galaxy_s4_firmware.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2013-4764MEDIUMCVSS 4.3v1.42019-12-27
CVE-2013-4764 [MEDIUM] CWE-276 CVE-2013-4764: Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
nvd
CVE-2015-1801CRITICALCVSS 9.8vi9500xxuemk82017-08-24
CVE-2015-1801 [CRITICAL] CWE-119 CVE-2015-1801: The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows a The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory corruption) or gain privileges.
nvd
CVE-2015-1800HIGHCVSS 7.5vi9500xxuemk82017-08-24
CVE-2015-1800 [HIGH] CWE-200 CVE-2015-1800: The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows a The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive information.
nvd
CVE-2016-4031MEDIUMCVSS 6.8vi9505xxuhoj22017-04-13
CVE-2016-4031 [MEDIUM] CWE-284 CVE-2016-4031: Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices allow attackers to send AT commands by plugging the device into a Linux host, aka SVE-2016-5301.
nvd
CVE-2016-4032MEDIUMCVSS 4.6vi9505xxuhoj22017-04-13
CVE-2016-4032 [MEDIUM] CWE-284 CVE-2016-4032: Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices do not block AT+USBDEBUG and AT+WIFIVALUE, which allows attackers to modify Android settings by leveraging AT
nvd
CVE-2016-4030MEDIUMCVSS 6.8vi9505xxuhoj22017-04-13
CVE-2016-4030 [MEDIUM] CWE-284 CVE-2016-4030: Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, a
nvd