VYPR

Android

by Samsung Mobile

CVEs (487)

  • CVE-2023-21428MedFeb 9, 2023
    risk 0.26cvss 4.0epss 0.00

    Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.

  • CVE-2026-21062LowAug 10, 2026
    risk 0.21cvss 3.3epss 0.00

    Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

  • CVE-2026-21027LowJun 5, 2026
    risk 0.21cvss 3.3epss 0.00

    Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

  • CVE-2026-21012LowApr 13, 2026
    risk 0.21cvss 3.3epss 0.00

    External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.

  • CVE-2026-20992LowMar 16, 2026
    risk 0.21cvss 3.3epss 0.00

    Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.

  • CVE-2026-20972LowJan 9, 2026
    risk 0.21cvss 3.3epss 0.00

    Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.

  • CVE-2024-34640LowSep 4, 2024
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.

  • CVE-2024-34602LowJul 8, 2024
    risk 0.21cvss 3.3epss 0.00

    Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

  • CVE-2024-20836LowMar 5, 2024
    risk 0.21cvss 3.3epss 0.00

    Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.

  • CVE-2024-20834LowMar 5, 2024
    risk 0.21cvss 3.3epss 0.00

    The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.

  • CVE-2024-20810LowFeb 6, 2024
    risk 0.21cvss 3.3epss 0.00

    Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-20805LowJan 4, 2024
    risk 0.21cvss 3.3epss 0.00

    Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.

  • CVE-2023-42556LowDec 5, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.

  • CVE-2023-30648LowJul 6, 2023
    risk 0.21cvss 3.3epss 0.00

    Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.

  • CVE-2023-21452LowMar 16, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.

  • CVE-2023-21436LowFeb 9, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.

  • CVE-2026-21006LowApr 13, 2026
    risk 0.16cvss 2.4epss 0.00

    Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.

  • CVE-2026-20989LowMar 16, 2026
    risk 0.16cvss 2.4epss 0.00

    Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.

  • CVE-2025-21046LowOct 10, 2025
    risk 0.16cvss 2.4epss 0.00

    Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list.

  • CVE-2024-49414LowDec 3, 2024
    risk 0.16cvss 2.4epss 0.00

    Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.

Page 24 of 25