VYPR

Android

by Samsung Mobile

CVEs (475)

  • CVE-2023-21441HigFeb 9, 2023
    risk 0.48cvss 7.4epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.

  • CVE-2025-20957HigMay 7, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.

  • CVE-2025-20903HigMar 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.

  • CVE-2024-34614HigAug 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-34612HigAug 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-20878HigJun 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-20877HigJun 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-20849HigApr 2, 2024
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-42568HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.

  • CVE-2023-42567HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.

  • CVE-2023-42566HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-42565HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.

  • CVE-2023-21420HigFeb 9, 2023
    risk 0.47cvss 7.3epss 0.00

    Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.

  • CVE-2025-21050HigOct 10, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

  • CVE-2025-21006HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.

  • CVE-2025-20890HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-20888HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-20882HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-20881HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2024-49413HigDec 3, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.

Page 5 of 24