VYPR

mobile devices

by Samsung Mobile

CVEs (1,006)

  • CVE-2024-49408MedNov 6, 2024
    risk 0.42cvss 6.4epss 0.00

    Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.

  • CVE-2024-20892MedJul 2, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.

  • CVE-2024-20881MedJun 4, 2024
    risk 0.42cvss 6.4epss 0.00

    Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local privileged attackers lead to potential arbitrary code execution.

  • CVE-2024-20880MedJun 4, 2024
    risk 0.42cvss 6.4epss 0.00

    Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.

  • CVE-2024-20832MedMar 5, 2024
    risk 0.42cvss 6.4epss 0.00

    Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2024-20831MedMar 5, 2024
    risk 0.42cvss 6.4epss 0.00

    Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2022-39902MedDec 8, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.

  • CVE-2022-39901MedDec 8, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.

  • CVE-2022-39854MedOct 7, 2022
    risk 0.42cvss 6.4epss 0.00

    Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.

  • CVE-2022-25818MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.

  • CVE-2021-25518MedDec 8, 2021
    risk 0.42cvss 6.4epss 0.00

    An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-25516MedDec 8, 2021
    risk 0.42cvss 6.4epss 0.00

    An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.

  • CVE-2021-25481MedOct 6, 2021
    risk 0.42cvss 6.4epss 0.00

    An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of Exynos CP Memory.

  • CVE-2021-25449MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.00

    An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor process.

  • CVE-2021-25427MedJul 8, 2021
    risk 0.42cvss 6.5epss 0.00

    SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information

  • CVE-2021-25416MedJun 11, 2021
    risk 0.42cvss 6.5epss 0.00

    Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.

  • CVE-2018-21092MedApr 8, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by the DeviceTest application via an NFC tag. The Samsung ID is SVE-2017-10885 (January 2018).

  • CVE-2017-18695MedApr 7, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) can discover a user's credentials, during an email account login, via an EAS autodiscover packet. The Samsung ID is SVE-2016-7654…

  • CVE-2016-11034MedApr 7, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Qt 5.7 allows attackers to trigger a system crash via a malformed image. The Samsung ID is SVE-2016-6560 (October 2016).

  • CVE-2019-20609MedMar 24, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can use Smartwatch to view Secure Folder notification content. The Samsung ID is SVE-2019-13899 (April 2019).

Page 20 of 51