VYPR

mobile devices

by Samsung Mobile

CVEs (1,006)

  • CVE-2025-20948MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.

  • CVE-2025-20947MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.

  • CVE-2025-20938MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.

  • CVE-2025-20934MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.

  • CVE-2024-34594MedJul 2, 2024
    risk 0.36cvss 5.5epss 0.00

    Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.

  • CVE-2024-20896MedJul 2, 2024
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-20864MedMay 7, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.

  • CVE-2024-20859MedMay 7, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.

  • CVE-2024-20843MedApr 2, 2024
    risk 0.36cvss 5.6epss 0.00

    Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2023-42557MedDec 5, 2023
    risk 0.36cvss 5.6epss 0.00

    Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.

  • CVE-2023-42527MedNov 7, 2023
    risk 0.36cvss 5.6epss 0.00

    Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.

  • CVE-2023-30732MedOct 4, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.

  • CVE-2023-30698MedAug 10, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.

  • CVE-2023-21504MedMay 4, 2023
    risk 0.36cvss 5.6epss 0.01

    Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

  • CVE-2023-21503MedMay 4, 2023
    risk 0.36cvss 5.6epss 0.01

    Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

  • CVE-2023-21494MedMay 4, 2023
    risk 0.36cvss 5.6epss 0.01

    Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

  • CVE-2022-25815MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

  • CVE-2022-25814MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    PendingIntent hijacking vulnerability in Wearable Manager Installer prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

  • CVE-2022-22291MedFeb 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Logging of excessive data vulnerability in telephony prior to SMR Feb-2022 Release 1 allows privileged attackers to get Cell Location Information through log of user device.

  • CVE-2022-22271MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.00

    A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy data from arbitrary memory.

Page 28 of 51