Android Applications Updates
SVE-2023-1705(CVE-2024-34621): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1706(CVE-2024-34622): Out-of-bounds write in Samsung Notes
Severity: High
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds write in appending paragraph in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1707(CVE-2024-34623): Out-of-bounds write in Samsung Notes
Severity: High
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds write in applying connected information in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1709(CVE-2024-34624): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1712(CVE-2024-34625): Out-of-bounds read validation in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1713(CVE-2024-34626): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds read in applying own binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1715(CVE-2024-34627): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds read in parsing implemention in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1716(CVE-2024-34628): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1717(CVE-2024-34629): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds read in applying binary with text common object in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1719(CVE-2024-34630): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds read in applying own binary with textbox in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1721(CVE-2024-34631): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 23, 2023
Description: Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
The patch adds proper input validation.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1726(CVE-2024-34632): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 25, 2023
Description: Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
The patch adds proper boundary check.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1727(CVE-2024-34633): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 25, 2023
Description: Out-of-bounds read in parsing object header in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
The patch adds proper boundary check.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1734(CVE-2024-34634): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 26, 2023
Description: Out-of-bounds read in parsing connected object list in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
The patch adds proper boundary check.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2023-1735(CVE-2024-34635): Out-of-bounds read in Samsung Notes
Severity: Moderate
Resolved version: 4.4.21.62
Reported on: September 26, 2023
Description: Out-of-bounds read in parsing textbox object in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.
The patch adds proper boundary check.
Acknowledgement: Ye Zhang (@VAR10CK) of Baidu Security
SVE-2024-0979(CVE-2024-34636): Use of implicit intent for sensitive communication in Samsung Email
Severity: Moderate
Resolved version: 6.1.94.2
Reported on: April 20, 2024
Description: Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.
The patch adds proper configuration.
Acknowledgement: khilli
PC Updates
Intel patches are included in this Security Maintenance Release with the following CVE item:
Moderate
CVE-2024-23198, CVE-2024-24984, CVE-2024-25563, CVE-2024-28049
※ Please see Intel Product Security Center Advisories for detailed information on Intel patches.