VYPR

mobile devices

by Samsung Mobile

CVEs (1,006)

  • CVE-2023-30709HigSep 6, 2023
    risk 0.51cvss 7.9epss 0.00

    Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.

  • CVE-2023-30679HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-30649HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

  • CVE-2023-30647HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

  • CVE-2023-30646HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

  • CVE-2023-30645HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

  • CVE-2023-30644HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

  • CVE-2022-24931HigMar 10, 2022
    risk 0.51cvss 7.9epss 0.00

    Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbitrary activity without a proper permission

  • CVE-2021-25502HigNov 5, 2021
    risk 0.51cvss 7.9epss 0.00

    A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.

  • CVE-2021-25470HigOct 6, 2021
    risk 0.51cvss 7.9epss 0.00

    An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

  • CVE-2021-25428HigJul 8, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permission without user confirmation in limited circumstances.

  • CVE-2021-25414HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary files with Samsung Contacts privilege.

  • CVE-2021-25412HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.

  • CVE-2021-25408HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-25407HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.

  • CVE-2021-25361HigApr 9, 2021
    risk 0.51cvss 7.9epss 0.00

    An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.

  • CVE-2020-28343HigNov 8, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software. The NPU driver allows attackers to execute arbitrary code because of unintended write and read operations on memory. The Samsung ID is SVE-2020-18610…

  • CVE-2020-28342HigNov 8, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (China / India) software. The S Secure application allows attackers to bypass authentication for a locked Gallery application via the Reminder application. The Samsung ID is SVE-2020-18689 (November 2020).

  • CVE-2020-28341HigNov 8, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3K250AF Secure Element CC EAL 5+ chip allows attackers to execute arbitrary code and obtain sensitive information via a buffer overflow. The Samsung ID is SVE-2020-18632 (November…

  • CVE-2020-12751HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted JPEG data that is mishandled during decoding. The Samsung ID is SVE-2020-16943…

Page 9 of 51