VYPR

Mobile

by Samsung Mobile

CVEs (32)

  • CVE-2015-7896MedAug 24, 2017
    risk 0.46cvss 6.5epss 0.07

    LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.

  • CVE-2023-30671MedJul 6, 2023
    risk 0.41cvss 6.3epss 0.00

    Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.

  • CVE-2018-9140MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.

  • CVE-2015-7898MedJun 27, 2017
    risk 0.39cvss 5.5epss 0.01

    Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

  • CVE-2015-7895MedJun 27, 2017
    risk 0.39cvss 5.5epss 0.01

    Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

  • CVE-2018-10751MedMay 29, 2018
    risk 0.38cvss 5.3epss 0.08

    A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.

  • CVE-2016-4546MedFeb 13, 2017
    risk 0.36cvss 5.5epss 0.00

    Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a service call.

  • CVE-2017-5217MedJan 9, 2017
    risk 0.36cvss 5.5epss 0.01

    Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS. The zero-permission app will create an active install session for a separate app…

  • CVE-2016-9567MedNov 23, 2016
    risk 0.36cvss 5.5epss 0.01

    The mDNIe system service on Samsung Mobile S7 devices with M(6.0) software does not properly restrict setmDNIeScreenCurtain API calls, enabling attackers to control a device's screen. This can be exploited via a crafted application to eavesdrop after phone shutdown or record a…

  • CVE-2026-20974MedJan 9, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.

  • CVE-2024-34583MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.

  • CVE-2014-8346Oct 24, 2014
    risk 0.00cvss —epss 0.02

    The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile…

Page 2 of 2