VYPR

Contacts

by Samsung Mobile

CVEs (8)

  • CVE-2019-20613HigMar 24, 2020
    risk 0.53cvss 8.1epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is time-based SQL injection in Contacts. The Samsung ID is SVE-2018-13452 (March 2019).

  • CVE-2021-25414HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary files with Samsung Contacts privilege.

  • CVE-2025-21050HigOct 10, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

  • CVE-2024-34674MedNov 6, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.

  • CVE-2022-39896MedDec 8, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.

  • CVE-2021-25524MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.

  • CVE-2023-42556LowDec 5, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.

  • CVE-2023-21436LowFeb 9, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.