CWE-925 · 19 записей
Improper Verification of Intent by Broadcast Receiver
CVE этого класса
19 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
37Наблюдать | CVE-2024-10576Эксплойта нет | Unauthorized factory reset of Infinix devicesinfinix mobile · com.transsion.agingfunction · CWE-925 | Критическая9,4 | — | 0,2 % | 4 дек. 2024 г. |
30Наблюдать | CVE-2023-42543Эксплойта нет | Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbsamsung · bixby voice · CWE-925 | Высокая7,5 | — | 0,5 % | 7 нояб. 2023 г. |
27Наблюдать | CVE-2026-20988Эксплойта нет | Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary samsung · android · CWE-925 | Средняя6,8 | — | 0,1 % | 16 мар. 2026 г. |
22Наблюдать | CVE-2024-20870Эксплойта нет | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to writsamsung · galaxy store · CWE-925 | Средняя5,5 | — | 0,1 % | 7 мая 2024 г. |
22Наблюдать | CVE-2025-20951Эксплойта нет | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to writsamsung · galaxy store · CWE-925 | Средняя5,5 | — | 0,1 % | 8 апр. 2025 г. |
22Наблюдать | CVE-2025-20972Эксплойта нет | Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flosamsung · flow · CWE-925 | Средняя5,5 | — | 0,1 % | 7 мая 2025 г. |
22Наблюдать | CVE-2023-44126Эксплойта нет | Call management - Implicit intents disclose telephony data such as phone numbers, call states, contactslg · v60 thin q 5g · CWE-925 | Средняя5,5 | — | 0,1 % | 27 сент. 2023 г. |
21Наблюдать | CVE-2026-33173Эксплойта нет | Rails Active Storage has possible content type bypass via metadata in direct uploadsrubyonrails · rails · CWE-925 | Средняя5,3 | — | 0,4 % | 23 мар. 2026 г. |
21Наблюдать | CVE-2024-34601Эксплойта нет | Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launcsamsung · galaxy store · CWE-925 | Средняя5,3 | — | 0,1 % | 2 июл. 2024 г. |
20Наблюдать | CVE-2024-20853Эксплойта нет | Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrarsamsung · galaxy themes · CWE-925 | Средняя5,1 | — | 0,2 % | 1 апр. 2024 г. |
20Наблюдать | CVE-2026-21106Эксплойта нет | Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable ensamsung mobile · samsung cloud assistant · CWE-925 | Средняя5,1 | — | 0,1 % | 9 сент. 2026 г. |
17Наблюдать | CVE-2025-20942Эксплойта нет | Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAIsamsung · android · CWE-925 | Средняя4,4 | — | 0,1 % | 8 апр. 2025 г. |
17Наблюдать | CVE-2025-20958Эксплойта нет | Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWsamsung · android · CWE-925 | Средняя4,4 | — | 0,1 % | 7 мая 2025 г. |
17Наблюдать | CVE-2025-21027Эксплойта нет | Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disamsung · android · CWE-925 | Средняя4,4 | — | 0,1 % | 3 сент. 2025 г. |
13Наблюдать | CVE-2024-20852Эксплойта нет | Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to accesamsung · smartthings · CWE-925 | Низкая3,3 | — | 0,1 % | 1 апр. 2024 г. |
13Наблюдать | CVE-2024-34600Эксплойта нет | Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copysamsung · flow · CWE-925 | Низкая3,3 | — | 0,1 % | 2 июл. 2024 г. |
13Наблюдать | CVE-2025-21039Эксплойта нет | Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modifysamsung · sassistant · CWE-925 | Низкая3,3 | — | 0,1 % | 3 сент. 2025 г. |
13Наблюдать | CVE-2025-21040Эксплойта нет | Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerarsamsung · sassistant · CWE-925 | Низкая3,3 | — | 0,1 % | 3 сент. 2025 г. |
13Наблюдать | CVE-2025-21038Эксплойта нет | Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modifsamsung · sassistant · CWE-925 | Низкая3,3 | — | 0,1 % | 3 сент. 2025 г. |
- CVE-2024-1057637Наблюдать
Unauthorized factory reset of Infinix devices
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %infinix mobile · com.transsion.agingfunction4 дек. 2024 г.
- CVE-2023-4254330Наблюдать
Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arb
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %samsung · bixby voice7 нояб. 2023 г.
- CVE-2026-2098827Наблюдать
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary
СредняяCVSS 6,8Эксплойта нетEPSS 0 %samsung · android16 мар. 2026 г.
- CVE-2024-2087022Наблюдать
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to writ
СредняяCVSS 5,5Эксплойта нетEPSS 0 %samsung · galaxy store7 мая 2024 г.
- CVE-2025-2095122Наблюдать
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to writ
СредняяCVSS 5,5Эксплойта нетEPSS 0 %samsung · galaxy store8 апр. 2025 г.
- CVE-2025-2097222Наблюдать
Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flo
СредняяCVSS 5,5Эксплойта нетEPSS 0 %samsung · flow7 мая 2025 г.
- CVE-2023-4412622Наблюдать
Call management - Implicit intents disclose telephony data such as phone numbers, call states, contacts
СредняяCVSS 5,5Эксплойта нетEPSS 0 %lg · v60 thin q 5g27 сент. 2023 г.
- CVE-2026-3317321Наблюдать
Rails Active Storage has possible content type bypass via metadata in direct uploads
СредняяCVSS 5,3Эксплойта нетEPSS 0 %rubyonrails · rails23 мар. 2026 г.
- CVE-2024-3460121Наблюдать
Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launc
СредняяCVSS 5,3Эксплойта нетEPSS 0 %samsung · galaxy store2 июл. 2024 г.
- CVE-2024-2085320Наблюдать
Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrar
СредняяCVSS 5,1Эксплойта нетEPSS 0 %samsung · galaxy themes1 апр. 2024 г.
- CVE-2026-2110620Наблюдать
Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable en
СредняяCVSS 5,1Эксплойта нетEPSS 0 %samsung mobile · samsung cloud assistant9 сент. 2026 г.
- CVE-2025-2094217Наблюдать
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAI
СредняяCVSS 4,4Эксплойта нетEPSS 0 %samsung · android8 апр. 2025 г.
- CVE-2025-2095817Наблюдать
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoW
СредняяCVSS 4,4Эксплойта нетEPSS 0 %samsung · android7 мая 2025 г.
- CVE-2025-2102717Наблюдать
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily di
СредняяCVSS 4,4Эксплойта нетEPSS 0 %samsung · android3 сент. 2025 г.
- CVE-2024-2085213Наблюдать
Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to acce
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %samsung · smartthings1 апр. 2024 г.
- CVE-2024-3460013Наблюдать
Improper verification of intent by broadcast receiver vulnerability in Samsung Flow prior to version 4.9.13.0 allows local attackers to copy
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %samsung · flow2 июл. 2024 г.
- CVE-2025-2103913Наблюдать
Improper verification of intent by SystemExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %samsung · sassistant3 сент. 2025 г.
- CVE-2025-2104013Наблюдать
Improper verification of intent by ExternalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modify itinerar
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %samsung · sassistant3 сент. 2025 г.
- CVE-2025-2103813Наблюдать
Improper verification of intent by SamsungExceptionalBroadcastReceiver in S Assistant prior to version 9.3.2 allows local attackers to modif
НизкаяCVSS 3,3Эксплойта нетEPSS 0 %samsung · sassistant3 сент. 2025 г.