VYPR

Android

by Samsung Mobile

CVEs (475)

  • CVE-2023-30715MedSep 6, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.

  • CVE-2023-30711MedSep 6, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.

  • CVE-2023-30707MedSep 6, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege.

  • CVE-2023-21495MedMay 4, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.

  • CVE-2023-21461MedMar 16, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.

  • CVE-2023-21449MedMar 16, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.

  • CVE-2023-21442MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information.

  • CVE-2023-21437MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.

  • CVE-2023-21429MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.

  • CVE-2023-21428MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.

  • CVE-2026-21027LowJun 5, 2026
    risk 0.21cvss 3.3epss 0.00

    Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

  • CVE-2026-21012LowApr 13, 2026
    risk 0.21cvss 3.3epss 0.00

    External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.

  • CVE-2026-20992LowMar 16, 2026
    risk 0.21cvss 3.3epss 0.00

    Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.

  • CVE-2026-20972LowJan 9, 2026
    risk 0.21cvss 3.3epss 0.00

    Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.

  • CVE-2024-34640LowSep 4, 2024
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.

  • CVE-2024-34602LowJul 8, 2024
    risk 0.21cvss 3.3epss 0.00

    Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

  • CVE-2024-20836LowMar 5, 2024
    risk 0.21cvss 3.3epss 0.00

    Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.

  • CVE-2024-20834LowMar 5, 2024
    risk 0.21cvss 3.3epss 0.00

    The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.

  • CVE-2024-20810LowFeb 6, 2024
    risk 0.21cvss 3.3epss 0.00

    Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-20805LowJan 4, 2024
    risk 0.21cvss 3.3epss 0.00

    Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.

Page 23 of 24