mobile devices
CVEs (1,006)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-20948 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory. | ||
| CVE-2025-20947 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20938 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts. | ||
| CVE-2025-20934 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege. | ||
| CVE-2024-34594 | Med | 0.36 | 5.5 | 0.00 | Jul 2, 2024 | Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address. | ||
| CVE-2024-20896 | Med | 0.36 | 5.5 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20864 | Med | 0.36 | 5.5 | 0.00 | May 7, 2024 | Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources. | ||
| CVE-2024-20859 | Med | 0.36 | 5.5 | 0.00 | May 7, 2024 | Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege. | ||
| CVE-2024-20843 | Med | 0.36 | 5.6 | 0.00 | Apr 2, 2024 | Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code. | ||
| CVE-2023-42557 | Med | 0.36 | 5.6 | 0.00 | Dec 5, 2023 | Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code. | ||
| CVE-2023-42527 | Med | 0.36 | 5.6 | 0.00 | Nov 7, 2023 | Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information. | ||
| CVE-2023-30732 | Med | 0.36 | 5.5 | 0.00 | Oct 4, 2023 | Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number. | ||
| CVE-2023-30698 | Med | 0.36 | 5.5 | 0.00 | Aug 10, 2023 | Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege. | ||
| CVE-2023-21504 | Med | 0.36 | 5.6 | 0.01 | May 4, 2023 | Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access. | ||
| CVE-2023-21503 | Med | 0.36 | 5.6 | 0.01 | May 4, 2023 | Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access. | ||
| CVE-2023-21494 | Med | 0.36 | 5.6 | 0.01 | May 4, 2023 | Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access. | ||
| CVE-2022-25815 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2022 | PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent. | ||
| CVE-2022-25814 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2022 | PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent. | ||
| CVE-2022-22291 | Med | 0.36 | 5.5 | 0.00 | Feb 11, 2022 | Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device. | ||
| CVE-2022-22271 | Med | 0.36 | 5.5 | 0.00 | Jan 10, 2022 | A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy data from arbitrary memory. |
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.
- risk 0.36cvss 5.5epss 0.00
Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.36cvss 5.5epss 0.00
Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.
- risk 0.36cvss 5.5epss 0.00
Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.
- risk 0.36cvss 5.6epss 0.00
Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code.
- risk 0.36cvss 5.6epss 0.00
Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.
- risk 0.36cvss 5.6epss 0.00
Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.
- risk 0.36cvss 5.5epss 0.00
Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.
- risk 0.36cvss 5.5epss 0.00
Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.
- risk 0.36cvss 5.6epss 0.01
Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
- risk 0.36cvss 5.6epss 0.01
Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
- risk 0.36cvss 5.6epss 0.01
Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
- risk 0.36cvss 5.5epss 0.00
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
- risk 0.36cvss 5.5epss 0.00
PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
- risk 0.36cvss 5.5epss 0.00
Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device.
- risk 0.36cvss 5.5epss 0.00
A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy data from arbitrary memory.
Page 28 of 51