VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2025-54450HigJul 23, 2025
    risk 0.47cvss 7.2epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

  • CVE-2025-20968HigMay 7, 2025
    risk 0.47cvss 7.2epss 0.00

    Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows remote attackers to access data and perform internal operations within Samsung Gallery.

  • CVE-2025-20957HigMay 7, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.

  • CVE-2025-20931HigMar 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Out-of-bounds write in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute arbitrary code.

  • CVE-2025-20929HigMar 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Out-of-bounds write in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to execute arbitrary code.

  • CVE-2025-20903HigMar 6, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.

  • CVE-2024-34660HigSep 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

  • CVE-2024-34656HigSep 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Path traversal in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.

  • CVE-2024-34614HigAug 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-34612HigAug 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-20878HigJun 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-20877HigJun 4, 2024
    risk 0.47cvss 7.3epss 0.00

    Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-31954HigMay 14, 2024
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directory and DLL files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (An attacker…

  • CVE-2024-20849HigApr 2, 2024
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2024-23769HigFeb 7, 2024
    risk 0.47cvss 7.3epss 0.00

    Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.

  • CVE-2023-42568HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.

  • CVE-2023-42567HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.

  • CVE-2023-42566HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-42565HigDec 5, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.

  • CVE-2023-35649HigOct 11, 2023
    risk 0.47cvss 7.2epss 0.00

    In several functions of Exynos modem files, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-41929HigSep 18, 2023
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in Samsung Memory Card & UFD Authentication Utility PC Software before 1.0.1 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows to exploit this vulnerability.)

  • CVE-2022-4894HigAug 16, 2023
    risk 0.47cvss 7.3epss 0.00

    Certain HP and Samsung Printer software packages may potentially be vulnerable to elevation of privilege due to Uncontrolled Search Path Element.

  • CVE-2023-21420HigFeb 9, 2023
    risk 0.47cvss 7.3epss 0.00

    Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.

  • CVE-2022-39858HigOct 7, 2022
    risk 0.47cvss 7.3epss 0.00

    Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamera privilege.

  • CVE-2022-39857HigOct 7, 2022
    risk 0.47cvss 7.3epss 0.00

    Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege.

  • CVE-2022-36833HigAug 5, 2022
    risk 0.47cvss 7.3epss 0.00

    Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name.

  • CVE-2022-30755HigJul 12, 2022
    risk 0.47cvss 7.3epss 0.00

    Improper authentication vulnerability in AppLock prior to SMR Jul-2022 Release 1 allows attacker to bypass password confirm activity by hijacking the implicit intent.

  • CVE-2022-25154HigApr 5, 2022
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows 7, 10, or 11 to exploit this vulnerability.)

  • CVE-2021-25500HigNov 5, 2021
    risk 0.47cvss 7.2epss 0.00

    A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.

  • CVE-2021-25498HigOct 6, 2021
    risk 0.47cvss 7.3epss 0.00

    A possible buffer overflow vulnerability in maetd_eco_cb_mode of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.

  • CVE-2021-25497HigOct 6, 2021
    risk 0.47cvss 7.3epss 0.00

    A possible buffer overflow vulnerability in maetd_cpy_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.

  • CVE-2021-25496HigOct 6, 2021
    risk 0.47cvss 7.3epss 0.00

    A possible buffer overflow vulnerability in maetd_dec_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.

  • CVE-2021-25495HigOct 6, 2021
    risk 0.47cvss 7.3epss 0.00

    A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.

  • CVE-2021-25492HigOct 6, 2021
    risk 0.47cvss 7.3epss 0.00

    Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.

  • CVE-2021-25479HigOct 6, 2021
    risk 0.47cvss 7.2epss 0.01

    A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-25478HigOct 6, 2021
    risk 0.47cvss 7.2epss 0.01

    A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2018-21071HigApr 8, 2020
    risk 0.47cvss 7.3epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.0) software. Because of an unprotected intent, an attacker can read arbitrary files and emails, and take over an email account. The Samsung ID is SVE-2018-11633 (May 2018).

  • CVE-2017-18649HigApr 7, 2020
    risk 0.47cvss 7.2epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can boot a device with root privileges because the bootloader for the Qualcomm MSM8998 chipset lacks an integrity check of the system image, aka the "SamFAIL" issue. The Samsung ID is…

  • CVE-2016-3850HigAug 5, 2016
    risk 0.47cvss 7.3epss 0.00

    Integer overflow in app/aboot/aboot.c in the Qualcomm bootloader in Android before 2016-08-05 on Nexus 5, 5X, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted header field in a boot image, aka Android internal bug 27917291 and Qualcomm internal bug…

  • CVE-2026-21100HigSep 9, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.

  • CVE-2026-21059HigAug 10, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

  • CVE-2026-21058HigAug 10, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

  • CVE-2026-21033HigJun 5, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

  • CVE-2026-21032HigJun 5, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

  • CVE-2026-25208HigApr 13, 2026
    risk 0.46cvss 8.1epss 0.00

    Integer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.

  • CVE-2025-54601HigApr 6, 2026
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor amd Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a double free. An attacker can trigger a race…

  • CVE-2025-54602HigApr 6, 2026
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Improper synchronization on a global variable leads to a use-after-free. An attacker can trigger a race…

  • CVE-2025-52519HigJan 5, 2026
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Improper validation of user-space input in the issimian device driver leads to information disclosure and a denial of service.

  • CVE-2025-21079HigNov 5, 2025
    risk 0.46cvss 7.1epss 0.01

    Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-21061HigOct 10, 2025
    risk 0.46cvss 7.1epss 0.00

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interaction is required for triggering this vulnerability.

Page 15 of 47