VYPR

mobile devices

by Samsung Mobile

CVEs (1,006)

  • CVE-2024-34612HigAug 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-20878HigJun 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-20877HigJun 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-20849HigApr 2, 2024
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-42568HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.

  • CVE-2023-42567HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.

  • CVE-2023-42566HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-42565HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.

  • CVE-2023-21420HigFeb 9, 2023
    risk 0.47cvss 7.3epss 0.00

    Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.

  • CVE-2022-30755HigJul 12, 2022
    risk 0.47cvss 7.3epss 0.00

    Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.

  • CVE-2021-25500HigNov 5, 2021
    risk 0.47cvss 7.2epss 0.00

    A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.

  • CVE-2021-25479HigOct 6, 2021
    risk 0.47cvss 7.2epss 0.01

    A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-25478HigOct 6, 2021
    risk 0.47cvss 7.2epss 0.01

    A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2018-21071HigApr 8, 2020
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.0) software. Because of an unprotected intent, an attacker can read arbitrary files and emails, and take over an email account. The Samsung ID is SVE-2018-11633 (May 2018).

  • CVE-2017-18649HigApr 7, 2020
    risk 0.47cvss 7.2epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can boot a device with root privileges because the bootloader for the Qualcomm MSM8998 chipset lacks an integrity check of the system image, aka the "SamFAIL" issue. The Samsung ID is…

  • CVE-2025-21050HigOct 10, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

  • CVE-2025-20890HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-20888HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-20882HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-20881HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

Page 15 of 51