VYPR

Android

by Samsung Mobile

CVEs (475)

  • CVE-2023-21426MedFeb 9, 2023
    risk 0.28cvss 4.3epss 0.00

    Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.

  • CVE-2023-21425MedFeb 9, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.

  • CVE-2025-58476MedDec 2, 2025
    risk 0.27cvss 4.2epss 0.00

    Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.

  • CVE-2025-20999MedJul 8, 2025
    risk 0.27cvss 4.1epss 0.00

    Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.

  • CVE-2025-20886MedFeb 4, 2025
    risk 0.27cvss 4.1epss 0.00

    Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.

  • CVE-2024-34673MedNov 6, 2024
    risk 0.27cvss 4.1epss 0.00

    Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.

  • CVE-2024-20873MedJun 4, 2024
    risk 0.27cvss 4.2epss 0.00

    Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2024-20842MedApr 2, 2024
    risk 0.27cvss 4.2epss 0.00

    Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2024-20833MedMar 5, 2024
    risk 0.27cvss 4.1epss 0.00

    Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.

  • CVE-2023-21457MedMar 16, 2023
    risk 0.27cvss 4.1epss 0.00

    Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.

  • CVE-2025-21054MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.

  • CVE-2025-21053MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

  • CVE-2025-21052MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corruption.

  • CVE-2025-21051MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2025-21034MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.

  • CVE-2025-21033MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-21029MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.

  • CVE-2025-21026MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.

  • CVE-2023-21471MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.

  • CVE-2023-21470MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.

Page 20 of 24