Samsung Mobile Samsung Account vulnerabilities
16 known vulnerabilities affecting samsung_mobile/samsung_account.
Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM10LOW3
Vulnerabilities
Page 1 of 1
CVE-2022-39874MEDIUMCVSS 5.5≥ unspecified, < 13.5.02022-10-07
CVE-2022-39874 [MEDIUM] CWE-779 CVE-2022-39874: Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows at
Sensitive log information leakage vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
cvelistv5nvd
CVE-2022-39863MEDIUMCVSS 4.7≥ unspecified, < 13.5.01.32022-10-07
CVE-2022-39863 [MEDIUM] CWE-20 CVE-2022-39863: Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to a
Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permission.
cvelistv5nvd
CVE-2022-39875MEDIUMCVSS 4.4≥ unspecified, < 13.5.02022-10-07
CVE-2022-39875 [MEDIUM] CWE-284 CVE-2022-39875: Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attack
Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
cvelistv5nvd
CVE-2022-30735HIGHCVSS 7.5≥ unspecified, < 13.2.00.62022-06-07
CVE-2022-30735 [HIGH] CWE-200 CVE-2022-30735: Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers t
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the access_token without permission.
cvelistv5nvd
CVE-2022-30732HIGHCVSS 7.5≥ unspecified, < 13.2.00.62022-06-07
CVE-2022-30732 [HIGH] CWE-200 CVE-2022-30732: Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows
Exposure of Sensitive Information vulnerability in Samsung Account prior to version 13.2.00.6 allows attacker to access sensitive information via onActivityResult.
cvelistv5nvd
CVE-2022-30737MEDIUMCVSS 5.3≥ unspecified, < 13.2.00.62022-06-07
CVE-2022-30737 [MEDIUM] CWE-200 CVE-2022-30737: Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attacke
Implicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.
cvelistv5nvd
CVE-2022-30733MEDIUMCVSS 5.3≥ unspecified, < 13.2.00.62022-06-07
CVE-2022-30733 [MEDIUM] CWE-200 CVE-2022-30733: Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows a
Sensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.
cvelistv5nvd
CVE-2022-30739MEDIUMCVSS 4.3≥ unspecified, < 13.2.00.62022-06-07
CVE-2022-30739 [MEDIUM] CWE-269 CVE-2022-30739: Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers t
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get an user email or phone number with a normal level permission.
cvelistv5nvd
CVE-2022-30734MEDIUMCVSS 5.3≥ unspecified, < 13.2.00.62022-06-07
CVE-2022-30734 [MEDIUM] CWE-200 CVE-2022-30734: Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows
Sensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone number without permission.
cvelistv5nvd
CVE-2022-30736MEDIUMCVSS 5.3≥ unspecified, < 13.2.00.62022-06-07
CVE-2022-30736 [MEDIUM] CWE-200 CVE-2022-30736: Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers t
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
cvelistv5nvd
CVE-2022-30743MEDIUMCVSS 5.3≥ unspecified, < 13.2.00.62022-06-07
CVE-2022-30743 [MEDIUM] CWE-200 CVE-2022-30743: Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers t
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.
cvelistv5nvd
CVE-2022-25825MEDIUMCVSS 5.5≥ -, < 13.1.0.12022-03-10
CVE-2022-25825 [MEDIUM] CWE-287 CVE-2022-25825: Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers
Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.
cvelistv5nvd
CVE-2021-25403LOWCVSS 3.3≥ unspecified, < 10.8.0.4 in Android P(9.0) below, and 12.2.0.9 in Android Q(10.0) above2021-06-11
CVE-2021-25403 [LOW] CWE-200 CVE-2021-25403: Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and
Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.
cvelistv5nvd
CVE-2021-25381HIGHCVSS 7.8≥ Android P(9.0) and below, < 10.8.0.4≥ Android Q(10.0) and above, < 12.1.1.32021-04-09
CVE-2021-25381 [HIGH] CWE-285 CVE-2021-25381: Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
cvelistv5nvd
CVE-2021-25350LOWCVSS 3.9≥ Android Q(10.0), < 12.1.1.32021-03-25
CVE-2021-25350 [LOW] CWE-200 CVE-2021-25350: Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically pr
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.
cvelistv5nvd
CVE-2021-25351LOWCVSS 2.4≥ Android P(9.0) and below, < 10.7.07≥ Android Q(10.0), < 12.1.1.32021-03-25
CVE-2021-25351 [LOW] CWE-285 CVE-2021-25351: Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.
cvelistv5nvd