VYPR

Android

by Samsung Mobile

CVEs (475)

  • CVE-2025-21042HigKEVSep 12, 2025
    risk 0.70cvss 8.8epss 0.33

    Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

  • CVE-2025-21043HigKEVSep 12, 2025
    risk 0.69cvss 8.8epss 0.02

    Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

  • CVE-2020-8899CriMay 6, 2020
    risk 0.64cvss 9.8epss 0.06

    There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable phone can trigger a heap-based buffer overflow in the Quram…

  • CVE-2023-21456CriMar 16, 2023
    risk 0.59cvss 9.0epss 0.00

    Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.

  • CVE-2021-25487HigKEVOct 6, 2021
    risk 0.59cvss 7.3epss 0.01

    Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.

  • CVE-2025-20936HigApr 8, 2025
    risk 0.57cvss 8.8epss 0.00

    Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to escalate their privileges to root.

  • CVE-2023-21480HigSep 3, 2025
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2025-20979HigMay 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.

  • CVE-2024-34620HigAug 7, 2024
    risk 0.55cvss 8.4epss 0.00

    Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.

  • CVE-2024-20845HigApr 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds write vulnerability while releasing memory in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2024-20844HigApr 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds write vulnerability while parsing remaining codewords in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2024-20813HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2024-20812HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-42537HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

  • CVE-2023-42536HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

  • CVE-2023-42535HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30692HigOct 4, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30690HigOct 4, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30710HigSep 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30691HigAug 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.

Page 1 of 24