mobile devices
CVEs (1,006)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20594 | Med | 0.44 | 6.8 | 0.00 | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (Exynos chipsets) software. A heap overflow exists in the bootloader. The Samsung ID is SVE-2019-14371 (July 2019). | ||
| CVE-2020-10839 | Med | 0.44 | 6.8 | 0.00 | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card. The Samsung ID is SVE-2019-16193 (February 2020). | ||
| CVE-2026-20981 | Med | 0.43 | 6.6 | 0.00 | Feb 4, 2026 | Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege. | ||
| CVE-2025-20964 | Med | 0.43 | 6.6 | 0.00 | May 7, 2025 | Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2025-20963 | Med | 0.43 | 6.6 | 0.00 | May 7, 2025 | Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2024-34646 | Med | 0.43 | 6.6 | 0.00 | Sep 4, 2024 | Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service. | ||
| CVE-2024-20865 | Med | 0.43 | 6.6 | 0.00 | May 7, 2024 | Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images. | ||
| CVE-2024-20819 | Med | 0.43 | 6.6 | 0.00 | Feb 6, 2024 | Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow. | ||
| CVE-2024-20818 | Med | 0.43 | 6.6 | 0.00 | Feb 6, 2024 | Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow. | ||
| CVE-2024-20817 | Med | 0.43 | 6.6 | 0.00 | Feb 6, 2024 | Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow. | ||
| CVE-2023-42564 | Med | 0.43 | 6.6 | 0.00 | Dec 5, 2023 | Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege. | ||
| CVE-2023-42533 | Med | 0.43 | 6.6 | 0.00 | Nov 7, 2023 | Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel. | ||
| CVE-2022-27822 | Med | 0.43 | 6.6 | 0.00 | Apr 11, 2022 | Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission. | ||
| CVE-2021-25393 | Med | 0.43 | 6.6 | 0.00 | Jun 11, 2021 | Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data. | ||
| CVE-2025-20983 | Med | 0.42 | 6.4 | 0.00 | Jul 8, 2025 | Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2025-20982 | Med | 0.42 | 6.4 | 0.00 | Jul 8, 2025 | Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2025-20943 | Med | 0.42 | 6.4 | 0.00 | Apr 8, 2025 | Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption. | ||
| CVE-2025-20908 | Med | 0.42 | 6.5 | 0.00 | Mar 6, 2025 | Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting. | ||
| CVE-2025-20885 | Med | 0.42 | 6.4 | 0.00 | Feb 4, 2025 | Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memory corruption. | ||
| CVE-2024-49409 | Med | 0.42 | 6.4 | 0.00 | Nov 6, 2024 | Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability. |
- risk 0.44cvss 6.8epss 0.00
An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (Exynos chipsets) software. A heap overflow exists in the bootloader. The Samsung ID is SVE-2019-14371 (July 2019).
- risk 0.44cvss 6.8epss 0.00
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card. The Samsung ID is SVE-2019-16193 (February 2020).
- risk 0.43cvss 6.6epss 0.00
Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.
- risk 0.43cvss 6.6epss 0.00
Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.43cvss 6.6epss 0.00
Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.43cvss 6.6epss 0.00
Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.
- risk 0.43cvss 6.6epss 0.00
Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.
- risk 0.43cvss 6.6epss 0.00
Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
- risk 0.43cvss 6.6epss 0.00
Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
- risk 0.43cvss 6.6epss 0.00
Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
- risk 0.43cvss 6.6epss 0.00
Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
- risk 0.43cvss 6.6epss 0.00
Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.
- risk 0.43cvss 6.6epss 0.00
Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.
- risk 0.43cvss 6.6epss 0.00
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.
- risk 0.42cvss 6.4epss 0.00
Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.42cvss 6.4epss 0.00
Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.42cvss 6.4epss 0.00
Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.
- risk 0.42cvss 6.5epss 0.00
Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.
- risk 0.42cvss 6.4epss 0.00
Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memory corruption.
- risk 0.42cvss 6.4epss 0.00
Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.
Page 19 of 51