VYPR

Android

by Samsung Mobile

CVEs (475)

  • CVE-2023-30680HigAug 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

  • CVE-2023-30664HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30658HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30656HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.

  • CVE-2023-30655HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-21491HigMay 4, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.

  • CVE-2023-21439HigFeb 9, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.

  • CVE-2021-25395MedKEVJun 11, 2021
    risk 0.54cvss 6.4epss 0.00

    A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.

  • CVE-2021-25394MedKEVJun 11, 2021
    risk 0.54cvss 6.4epss 0.00

    A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.

  • CVE-2026-20990HigMar 16, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.

  • CVE-2024-49415HigDec 3, 2024
    risk 0.53cvss 8.1epss 0.01

    Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.

  • CVE-2023-21501HigMay 4, 2023
    risk 0.53cvss 8.2epss 0.00

    Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-21499HigMay 4, 2023
    risk 0.53cvss 8.2epss 0.00

    Out-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-21476HigSep 3, 2025
    risk 0.52cvss 8.0epss 0.00

    Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-21475HigSep 3, 2025
    risk 0.52cvss 8.0epss 0.00

    Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2024-20816HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.00

    Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

  • CVE-2024-20815HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.00

    Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

  • CVE-2021-25372MedKEVMar 26, 2021
    risk 0.52cvss 6.1epss 0.01

    An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

  • CVE-2021-25371MedKEVMar 26, 2021
    risk 0.52cvss 6.1epss 0.01

    A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

  • CVE-2021-25370MedKEVMar 26, 2021
    risk 0.52cvss 6.1epss 0.01

    An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

Page 2 of 24