VYPR

Android

by Samsung Mobile

CVEs (475)

  • CVE-2023-21469MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.

  • CVE-2025-21015MedAug 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

  • CVE-2025-20990MedAug 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.

  • CVE-2025-21003MedJul 8, 2025
    risk 0.26cvss 4.0epss 0.00

    Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-20993MedJun 4, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2025-20992MedJun 4, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory.

  • CVE-2025-20991MedJun 4, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.

  • CVE-2025-20980MedMay 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

  • CVE-2025-20962MedMay 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.

  • CVE-2025-20960MedMay 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.

  • CVE-2025-20909MedMar 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2024-34680MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-34679MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.

  • CVE-2024-34677MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.

  • CVE-2024-34652MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

  • CVE-2024-34650MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

  • CVE-2024-34647MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

  • CVE-2024-34618MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.

  • CVE-2024-34617MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.

  • CVE-2024-34603MedJul 8, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.

Page 21 of 24