mobile devices
CVEs (1,006)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-25489 | Low | 0.33 | 3.3 | 0.01 | KEV | Oct 6, 2021 | Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic. | |
| CVE-2021-25453 | Med | 0.33 | 5.1 | 0.00 | Sep 9, 2021 | Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information. | ||
| CVE-2021-25340 | Med | 0.33 | 5.1 | 0.00 | Mar 4, 2021 | Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State. | ||
| CVE-2023-42559 | Med | 0.32 | 4.9 | 0.00 | Dec 5, 2023 | Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time. | ||
| CVE-2022-39847 | Med | 0.32 | 4.9 | 0.00 | Oct 7, 2022 | Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to perform malicious actions. | ||
| CVE-2022-36849 | Med | 0.32 | 4.9 | 0.00 | Sep 9, 2022 | Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions. | ||
| CVE-2022-36847 | Med | 0.32 | 4.9 | 0.00 | Sep 9, 2022 | Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions. | ||
| CVE-2023-30720 | Med | 0.31 | 4.7 | 0.00 | Sep 6, 2023 | PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access. | ||
| CVE-2023-30701 | Med | 0.31 | 4.7 | 0.00 | Aug 10, 2023 | PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access. | ||
| CVE-2023-21490 | Med | 0.31 | 4.7 | 0.00 | May 4, 2023 | Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager. | ||
| CVE-2022-33727 | Med | 0.31 | 4.8 | 0.00 | Aug 5, 2022 | A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack. | ||
| CVE-2022-33723 | Med | 0.31 | 4.8 | 0.00 | Aug 5, 2022 | A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack. | ||
| CVE-2015-9546 | Med | 0.31 | 4.8 | 0.00 | Apr 10, 2020 | An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences… | ||
| CVE-2026-20974 | Med | 0.30 | 4.6 | 0.00 | Jan 9, 2026 | Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock. | ||
| CVE-2023-21467 | Med | 0.30 | 4.6 | 0.00 | Sep 3, 2025 | Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message. | ||
| CVE-2025-20884 | Med | 0.30 | 4.6 | 0.00 | Feb 4, 2025 | Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2025-20883 | Med | 0.30 | 4.6 | 0.00 | Feb 4, 2025 | Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2024-49402 | Med | 0.30 | 4.6 | 0.00 | Nov 6, 2024 | Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles. | ||
| CVE-2024-34674 | Med | 0.30 | 4.6 | 0.00 | Nov 6, 2024 | Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2024-34653 | Med | 0.30 | 4.6 | 0.00 | Sep 4, 2024 | Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege. |
- risk 0.33cvss 3.3epss 0.01
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
- risk 0.33cvss 5.1epss 0.00
Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.
- risk 0.33cvss 5.1epss 0.00
Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.
- risk 0.32cvss 4.9epss 0.00
Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.
- risk 0.32cvss 4.9epss 0.00
Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to perform malicious actions.
- risk 0.32cvss 4.9epss 0.00
Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.
- risk 0.32cvss 4.9epss 0.00
Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.
- risk 0.31cvss 4.7epss 0.00
PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.
- risk 0.31cvss 4.7epss 0.00
PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.
- risk 0.31cvss 4.7epss 0.00
Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.
- risk 0.31cvss 4.8epss 0.00
A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
- risk 0.31cvss 4.8epss 0.00
A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
- risk 0.31cvss 4.8epss 0.00
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences…
- risk 0.30cvss 4.6epss 0.00
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
- risk 0.30cvss 4.6epss 0.00
Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.
Page 34 of 51