mobile devices
CVEs (1,006)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-20866 | Med | 0.37 | 5.7 | 0.00 | May 7, 2024 | Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step. | ||
| CVE-2023-30731 | Med | 0.37 | 5.7 | 0.00 | Oct 4, 2023 | Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type. | ||
| CVE-2023-21502 | Med | 0.37 | 5.7 | 0.00 | May 4, 2023 | Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands. | ||
| CVE-2023-21422 | Med | 0.37 | 5.7 | 0.00 | Feb 9, 2023 | Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService. | ||
| CVE-2022-39899 | Med | 0.37 | 5.7 | 0.00 | Dec 8, 2022 | Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture. | ||
| CVE-2022-26091 | Med | 0.37 | 5.7 | 0.00 | Apr 11, 2022 | Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard. | ||
| CVE-2021-25501 | Med | 0.37 | 5.7 | 0.00 | Nov 5, 2021 | An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers. | ||
| CVE-2026-20977 | Med | 0.36 | 5.5 | 0.00 | Feb 4, 2026 | Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning. | ||
| CVE-2026-20969 | Med | 0.36 | 5.5 | 0.00 | Jan 9, 2026 | Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-58475 | Med | 0.36 | 5.6 | 0.00 | Dec 2, 2025 | Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2025-21049 | Med | 0.36 | 5.5 | 0.00 | Oct 10, 2025 | Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-21028 | Med | 0.36 | 5.5 | 0.00 | Sep 3, 2025 | Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items. | ||
| CVE-2025-20998 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number. | ||
| CVE-2025-20988 | Med | 0.36 | 5.5 | 0.00 | Jun 4, 2025 | Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory. | ||
| CVE-2025-20986 | Med | 0.36 | 5.5 | 0.00 | Jun 4, 2025 | Improper access control in ScreenCapture for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to take screenshots. | ||
| CVE-2025-20985 | Med | 0.36 | 5.5 | 0.00 | Jun 4, 2025 | Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items. | ||
| CVE-2025-20961 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege. | ||
| CVE-2025-20955 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images. | ||
| CVE-2025-20954 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20952 | Med | 0.36 | 5.5 | 0.00 | Apr 9, 2025 | Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege. |
- risk 0.37cvss 5.7epss 0.00
Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.
- risk 0.37cvss 5.7epss 0.00
Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.
- risk 0.37cvss 5.7epss 0.00
Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands.
- risk 0.37cvss 5.7epss 0.00
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
- risk 0.37cvss 5.7epss 0.00
Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.
- risk 0.37cvss 5.7epss 0.00
Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard.
- risk 0.37cvss 5.7epss 0.00
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.6epss 0.00
Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
- risk 0.36cvss 5.5epss 0.00
Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Improper access control in ScreenCapture for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to take screenshots.
- risk 0.36cvss 5.5epss 0.00
Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items.
- risk 0.36cvss 5.5epss 0.00
Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.
- risk 0.36cvss 5.5epss 0.00
Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.
- risk 0.36cvss 5.5epss 0.00
Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.
Page 27 of 51