Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Exynos_1280_firmware
(Samsung)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 45 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2024-06-05 | CVE-2024-27370 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on hal_req->num_config_discovery_attr coming from userspace, which can lead to a heap overwrite. | Exynos_1280_firmware, Exynos_1330_firmware, Exynos_1380_firmware, Exynos_850_firmware, Exynos_980_firmware | 7.8 | ||
2024-06-05 | CVE-2024-27371 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead to a heap overwrite. | Exynos_1280_firmware, Exynos_1330_firmware, Exynos_1380_firmware, Exynos_850_firmware, Exynos_980_firmware | 7.8 | ||
2024-06-05 | CVE-2024-27372 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->infrastructure_ssid_len coming from userspace, which can lead to a heap overwrite. | Exynos_1280_firmware, Exynos_1330_firmware, Exynos_1380_firmware, Exynos_850_firmware, Exynos_980_firmware | 7.8 | ||
2024-06-05 | CVE-2024-27373 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->mesh_id_len coming from userspace, which can lead to a heap overwrite. | Exynos_1280_firmware, Exynos_1330_firmware, Exynos_1380_firmware, Exynos_850_firmware, Exynos_980_firmware | 7.8 | ||
2024-06-05 | CVE-2024-27374 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_publish_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead to a heap overwrite. | Exynos_1280_firmware, Exynos_1330_firmware, Exynos_1380_firmware, Exynos_850_firmware, Exynos_980_firmware | 7.8 | ||
2024-06-05 | CVE-2024-27375 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->sdea_service_specific_info_len coming from userspace, which can lead to a heap overwrite. | Exynos_1280_firmware, Exynos_1330_firmware, Exynos_1380_firmware, Exynos_850_firmware, Exynos_980_firmware | 7.8 | ||
2024-06-05 | CVE-2024-27376 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->rx_match_filter_len coming from userspace, which can lead to a heap overwrite. | Exynos_1280_firmware, Exynos_1330_firmware, Exynos_1380_firmware, Exynos_850_firmware, Exynos_980_firmware | 7.8 | ||
2024-06-05 | CVE-2024-27377 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_get_security_info_nl(), there is no input validation check on sec_info->key_info.body.pmk_info.pmk_len coming from userspace, which can lead to a heap overwrite. | Exynos_1280_firmware, Exynos_1330_firmware, Exynos_1380_firmware, Exynos_850_firmware, Exynos_980_firmware | 7.8 | ||
2024-06-05 | CVE-2024-27378 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_cert(), there is no input validation check on len coming from userspace, which can lead to a heap over-read. | Exynos_1280_firmware, Exynos_1330_firmware, Exynos_1380_firmware, Exynos_850_firmware, Exynos_980_firmware | 7.1 | ||
2024-06-05 | CVE-2024-27379 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite. | Exynos_1280_firmware, Exynos_1330_firmware, Exynos_1380_firmware, Exynos_850_firmware, Exynos_980_firmware | 7.8 |