VYPR

mobile devices

by Samsung Mobile

CVEs (1,006)

  • CVE-2019-20546MedMar 24, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom Wi-Fi chipsets) software. A denial-of-service attack can leverage a shared interface between Broadcom Bluetooth and Broadcom Wi-Fi. The Samsung ID is SVE-2019-15350 (November 2019).

  • CVE-2020-10845MedMar 24, 2020
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is a race condition leading to a use-after-free in MTP. The Samsung ID is SVE-2019-16520 (February 2020).

  • CVE-2020-10844MedMar 24, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.x), and Q(10.0) software. There is an out-of-bounds read vulnerability in media.audio_policy. The Samsung ID is SVE-2019-16333 (February 2020).

  • CVE-2023-21474MedSep 3, 2025
    risk 0.41cvss 6.3epss 0.00

    Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.

  • CVE-2025-20905MedFeb 4, 2025
    risk 0.41cvss 6.3epss 0.00

    Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.

  • CVE-2025-20904MedFeb 4, 2025
    risk 0.41cvss 6.3epss 0.00

    Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.

  • CVE-2023-42534MedNov 7, 2023
    risk 0.41cvss 6.3epss 0.00

    Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.

  • CVE-2023-30671MedJul 6, 2023
    risk 0.41cvss 6.3epss 0.00

    Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.

  • CVE-2023-21492MedKEVMay 4, 2023
    risk 0.41cvss 4.4epss 0.03

    Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

  • CVE-2021-25511MedDec 8, 2021
    risk 0.41cvss 6.3epss 0.00

    An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.

  • CVE-2021-25337MedKEVMar 4, 2021
    risk 0.41cvss 4.4epss 0.03

    Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

  • CVE-2026-20978MedFeb 4, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.

  • CVE-2025-21080MedDec 2, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.

  • CVE-2025-21004MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.

  • CVE-2025-21002MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.

  • CVE-2025-21001MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.

  • CVE-2025-21000MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.

  • CVE-2025-20997MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.

  • CVE-2025-20981MedJun 4, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-20944MedApr 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.

Page 21 of 51