VYPR

Android

by Samsung Mobile

CVEs (475)

  • CVE-2023-21503MedMay 4, 2023
    risk 0.36cvss 5.6epss 0.01

    Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

  • CVE-2023-21494MedMay 4, 2023
    risk 0.36cvss 5.6epss 0.01

    Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.

  • CVE-2023-21445MedFeb 9, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.

  • CVE-2016-4546MedFeb 13, 2017
    risk 0.36cvss 5.5epss 0.00

    Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a service call.

  • CVE-2017-5217MedJan 9, 2017
    risk 0.36cvss 5.5epss 0.01

    Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS. The zero-permission app will create an active install session for a separate app…

  • CVE-2023-21427MedFeb 9, 2023
    risk 0.35cvss 5.4epss 0.00

    Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition.

  • CVE-2026-20973MedJan 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.

  • CVE-2025-21047MedOct 10, 2025
    risk 0.34cvss 5.2epss 0.00

    Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.

  • CVE-2023-21479MedSep 3, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.

  • CVE-2023-21466MedSep 3, 2025
    risk 0.34cvss 5.3epss 0.00

    PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.

  • CVE-2025-20989MedJun 4, 2025
    risk 0.34cvss 5.2epss 0.00

    Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key.

  • CVE-2025-20987MedJun 4, 2025
    risk 0.34cvss 5.2epss 0.00

    Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a auth_token.

  • CVE-2025-20891MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

  • CVE-2025-20889MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

  • CVE-2025-20887MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in accessing table used for svp8t in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

  • CVE-2024-49422MedDec 31, 2024
    risk 0.34cvss 5.2epss 0.00

    Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.

  • CVE-2024-34592MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

  • CVE-2024-34591MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

  • CVE-2024-34590MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

  • CVE-2024-34589MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

Page 15 of 24