Mobile
CVEs (32)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-7896 | Med | 0.46 | 6.5 | 0.07 | Aug 24, 2017 | LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file. | ||
| CVE-2023-30671 | Med | 0.41 | 6.3 | 0.00 | Jul 6, 2023 | Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application. | ||
| CVE-2018-9140 | Med | 0.40 | 6.1 | 0.01 | Mar 30, 2018 | On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747. | ||
| CVE-2015-7898 | Med | 0.39 | 5.5 | 0.01 | Jun 27, 2017 | Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). | ||
| CVE-2015-7895 | Med | 0.39 | 5.5 | 0.01 | Jun 27, 2017 | Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). | ||
| CVE-2018-10751 | Med | 0.38 | 5.3 | 0.08 | May 29, 2018 | A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463. | ||
| CVE-2016-4546 | Med | 0.36 | 5.5 | 0.00 | Feb 13, 2017 | Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a service call. | ||
| CVE-2017-5217 | Med | 0.36 | 5.5 | 0.01 | Jan 9, 2017 | Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS. The zero-permission app will create an active install session for a separate app… | ||
| CVE-2016-9567 | Med | 0.36 | 5.5 | 0.01 | Nov 23, 2016 | The mDNIe system service on Samsung Mobile S7 devices with M(6.0) software does not properly restrict setmDNIeScreenCurtain API calls, enabling attackers to control a device's screen. This can be exploited via a crafted application to eavesdrop after phone shutdown or record a… | ||
| CVE-2026-20974 | Med | 0.30 | 4.6 | 0.00 | Jan 9, 2026 | Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock. | ||
| CVE-2024-34583 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier. | ||
| CVE-2014-8346 | 0.00 | — | 0.02 | Oct 24, 2014 | The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile… |
- risk 0.46cvss 6.5epss 0.07
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.
- risk 0.41cvss 6.3epss 0.00
Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.
- risk 0.40cvss 6.1epss 0.01
On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.
- risk 0.39cvss 5.5epss 0.01
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
- risk 0.39cvss 5.5epss 0.01
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
- risk 0.38cvss 5.3epss 0.08
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.
- risk 0.36cvss 5.5epss 0.00
Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a service call.
- risk 0.36cvss 5.5epss 0.01
Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS. The zero-permission app will create an active install session for a separate app…
- risk 0.36cvss 5.5epss 0.01
The mDNIe system service on Samsung Mobile S7 devices with M(6.0) software does not properly restrict setmDNIeScreenCurtain API calls, enabling attackers to control a device's screen. This can be exploited via a crafted application to eavesdrop after phone shutdown or record a…
- risk 0.30cvss 4.6epss 0.00
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
- risk 0.26cvss 4.0epss 0.00
Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.
- CVE-2014-8346Oct 24, 2014risk 0.00cvss —epss 0.02
The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile…
Page 2 of 2