VYPR

Android

by Samsung Mobile

CVEs (475)

  • CVE-2024-34610MedAug 7, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.

  • CVE-2024-20885MedJun 4, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.

  • CVE-2024-20811MedFeb 6, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.

  • CVE-2023-30667MedJul 6, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.

  • CVE-2023-21487MedMay 4, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.

  • CVE-2023-21484MedMay 4, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.

  • CVE-2023-21459MedMar 16, 2023
    risk 0.33cvss 5.0epss 0.00

    Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.

  • CVE-2023-21424MedFeb 9, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.

  • CVE-2023-21423MedFeb 9, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.

  • CVE-2021-25489LowKEVOct 6, 2021
    risk 0.33cvss 3.3epss 0.01

    Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

  • CVE-2023-42559MedDec 5, 2023
    risk 0.32cvss 4.9epss 0.00

    Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.

  • CVE-2023-30720MedSep 6, 2023
    risk 0.31cvss 4.7epss 0.00

    PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.

  • CVE-2023-30701MedAug 10, 2023
    risk 0.31cvss 4.7epss 0.00

    PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.

  • CVE-2023-21490MedMay 4, 2023
    risk 0.31cvss 4.7epss 0.00

    Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.

  • CVE-2026-20974MedJan 9, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.

  • CVE-2025-20884MedFeb 4, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.

  • CVE-2025-20883MedFeb 4, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.

  • CVE-2024-49402MedNov 6, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.

  • CVE-2024-34674MedNov 6, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.

  • CVE-2024-34653MedSep 4, 2024
    risk 0.30cvss 4.6epss 0.00

    Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

Page 17 of 24