VYPR

Android

by Samsung Mobile

CVEs (487)

  • CVE-2025-20960MedMay 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.

  • CVE-2025-20909MedMar 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2024-34680MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-34679MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.

  • CVE-2024-34677MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.

  • CVE-2024-34652MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

  • CVE-2024-34650MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

  • CVE-2024-34647MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

  • CVE-2024-34618MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.

  • CVE-2024-34617MedAug 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.

  • CVE-2024-34603MedJul 8, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.

  • CVE-2024-34583MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.

  • CVE-2024-20900MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.

  • CVE-2024-20899MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-20898MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-20897MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-20879MedJun 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2024-20875MedJun 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files.

  • CVE-2024-20860MedMay 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.

  • CVE-2024-20858MedMay 7, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.

Page 22 of 25