CVE-2024-27362
09.07.2024, 18:15
A vulnerability was discovered in Samsung Mobile Processors Exynos 1280, Exynos 2200, Exynos 1330, Exynos 1380, and Exynos 2400 where they do not properly check the length of the data, which can lead to a Information disclosure.Enginsight
Vendor | Product | Version |
---|---|---|
samsung | exynos_1280_firmware | - |
samsung | exynos_2200_firmware | - |
samsung | exynos_1330_firmware | - |
samsung | exynos_1380_firmware | - |
samsung | exynos_2400_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1284 - Improper Validation of Specified Quantity in InputThe product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References