VYPR

Android

by Samsung Mobile

CVEs (475)

  • CVE-2023-21435MedFeb 9, 2023
    risk 0.29cvss 4.4epss 0.00

    Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.

  • CVE-2023-21430MedFeb 9, 2023
    risk 0.29cvss 4.4epss 0.00

    An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.

  • CVE-2025-58480MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-58479MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-58478MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-58477MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-21075MedNov 5, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-21074MedNov 5, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-21055MedOct 10, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-21030MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background.

  • CVE-2025-21014MedAug 6, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2024-49411MedDec 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.

  • CVE-2024-20894MedJul 2, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.

  • CVE-2024-20856MedMay 7, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.

  • CVE-2023-30685MedAug 10, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.

  • CVE-2023-30684MedAug 10, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.

  • CVE-2023-30683MedAug 10, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.

  • CVE-2023-30682MedAug 10, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.

  • CVE-2023-30641MedJul 6, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.

  • CVE-2023-30640MedJul 6, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.

Page 19 of 24