VYPR

Android

by Samsung Mobile

CVEs (475)

  • CVE-2023-21498MedMay 4, 2023
    risk 0.39cvss 6.0epss 0.00

    Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.

  • CVE-2023-21453MedMar 16, 2023
    risk 0.39cvss 6.0epss 0.00

    Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.

  • CVE-2025-21032MedSep 3, 2025
    risk 0.38cvss 5.9epss 0.00

    Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.

  • CVE-2023-21468MedSep 3, 2025
    risk 0.38cvss 5.9epss 0.00

    Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.

  • CVE-2025-20892MedFeb 4, 2025
    risk 0.38cvss 5.9epss 0.00

    Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. User interaction is required for triggering this vulnerability.

  • CVE-2024-49410MedDec 3, 2024
    risk 0.38cvss 5.9epss 0.00

    Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-34678MedNov 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.

  • CVE-2024-34586MedJul 2, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.

  • CVE-2024-20901MedJul 2, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2024-20889MedJul 2, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.

  • CVE-2024-20846MedApr 2, 2024
    risk 0.38cvss 5.9epss 0.00

    Out-of-bounds write vulnerability while decoding hcr of libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-52432MedMar 5, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2023-42570MedDec 5, 2023
    risk 0.38cvss 5.9epss 0.00

    Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.

  • CVE-2023-42538MedNov 7, 2023
    risk 0.38cvss 5.9epss 0.00

    An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

  • CVE-2023-42532MedNov 7, 2023
    risk 0.38cvss 5.9epss 0.00

    Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.

  • CVE-2023-21421MedFeb 9, 2023
    risk 0.38cvss 5.9epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.

  • CVE-2025-21072MedDec 2, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21071MedNov 5, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21044MedOct 10, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2024-20866MedMay 7, 2024
    risk 0.37cvss 5.7epss 0.00

    Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.

Page 12 of 24