VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2025-21050HigOct 10, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

  • CVE-2025-53080HigJul 29, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated attackers to create arbitrary files in unintended locations on the filesystem

  • CVE-2025-21006HigJul 8, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.

  • CVE-2025-20890HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-20888HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-20882HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-20881HigFeb 4, 2025
    risk 0.46cvss 7.0epss 0.00

    Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.

  • CVE-2024-49413HigDec 3, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.

  • CVE-2024-39343HigDec 2, 2024
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, Modem 5123, and Modem 5300. The baseband software does not properly check the length specified by the MM (Mobility Management) module, which can lead…

  • CVE-2024-32670HigJul 10, 2024
    risk 0.46cvss —epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0.20.04 allows attackes to potentially identify the tag's location by scanning the BLE adversting.

  • CVE-2023-42561HigDec 5, 2023
    risk 0.46cvss 7.1epss 0.00

    Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.

  • CVE-2023-41112HigNov 8, 2023
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). A buffer copy, without checking the size of the…

  • CVE-2023-41111HigNov 8, 2023
    risk 0.46cvss 7.1epss 0.01

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, Automotive Processor, and Modem (Exynos 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, W920, Modem 5123, Modem 5300, and Auto T5123). Improper handling of a length parameter…

  • CVE-2023-21489HigMay 4, 2023
    risk 0.46cvss 7.1epss 0.00

    Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.

  • CVE-2022-39909HigDec 8, 2022
    risk 0.46cvss 7.1epss 0.00

    Insufficient verification of data authenticity vulnerability in Samsung Gear IconX PC Manager prior to version 2.1.221019.51 allows local attackers to create arbitrary file using symbolic link.

  • CVE-2022-39880HigNov 9, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.

  • CVE-2022-22292HigFeb 11, 2022
    risk 0.46cvss 7.1epss 0.00

    Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.

  • CVE-2021-25499HigOct 6, 2021
    risk 0.46cvss 7.1epss 0.00

    Intent redirection vulnerability in SamsungAccountSDKSigninActivity of Galaxy Store prior to version 4.5.32.4 allows attacker to access content provider of Galaxy Store.

  • CVE-2021-25410HigJun 11, 2021
    risk 0.46cvss 7.1epss 0.00

    Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated privilege.

  • CVE-2021-25399HigJun 11, 2021
    risk 0.46cvss 7.1epss 0.00

    Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.

  • CVE-2021-25388HigJun 11, 2021
    risk 0.46cvss 7.1epss 0.00

    Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.

  • CVE-2021-25356HigApr 9, 2021
    risk 0.46cvss 7.1epss 0.00

    An improper caller check vulnerability in Managed Provisioning prior to SMR APR-2021 Release 1 allows unprivileged application to install arbitrary application, grant device admin permission and then delete several installed application.

  • CVE-2021-25346HigMar 4, 2021
    risk 0.46cvss 7.1epss 0.01

    A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

  • CVE-2017-18680HigApr 7, 2020
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (tablets) software. The lockscreen interface allows Add User actions, leading to an unintended ability to access user data in external storage. The Samsung ID is SVE-2016-7797 (March 2017).

  • CVE-2019-20600HigMar 24, 2020
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.0) and P(9.0) (Exynos8890 chipsets) software. A use-after-free occurs in the MALI GPU driver. The Samsung ID is SVE-2019-13921-1 (May 2019).

  • CVE-2020-10843HigMar 24, 2020
    risk 0.46cvss 7.0epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (S.LSI chipsets) software. There are race conditions in the hdcp2 driver. The Samsung ID is SVE-2019-16296 (February 2020).

  • CVE-2020-10840HigMar 24, 2020
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) software. There is a kernel pointer leak in the vipx driver. The Samsung ID is SVE-2019-16293 (February 2020).

  • CVE-2019-20531HigMar 24, 2020
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi kernel drivers have an out-of-bounds Read. The Samsung IDs are SVE-2019-15692, SVE-2019-15693 (December 2019).

  • CVE-2018-10501HigSep 24, 2018
    risk 0.46cvss 7.0epss 0.00

    This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Notes Fixed in version 2.0.02.31. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The…

  • CVE-2018-10500HigSep 24, 2018
    risk 0.46cvss 7.0epss 0.00

    This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…

  • CVE-2018-10499HigSep 24, 2018
    risk 0.46cvss 7.0epss 0.00

    This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.…

  • CVE-2018-9142HigMar 30, 2018
    risk 0.46cvss 7.0epss 0.01

    On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation of a package signature and package name, aka SVE-2017-10932.

  • CVE-2015-7896MedAug 24, 2017
    risk 0.46cvss 6.5epss 0.07

    LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.

  • CVE-2026-21111MedSep 9, 2026
    risk 0.45cvss —epss 0.00

    Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory.

  • CVE-2026-21110MedSep 9, 2026
    risk 0.45cvss —epss 0.00

    Out-of-bounds write in libsavscmn.so prior to One UI 8.5 allows local attackers to execute arbitrary code.

  • CVE-2026-21107MedSep 9, 2026
    risk 0.45cvss —epss 0.00

    Out-of-bounds write in Samsung Notes prior to version 4.4.45.5 allows local attackers to write out-of-bounds memory.

  • CVE-2026-21037MedJun 5, 2026
    risk 0.45cvss —epss 0.00

    Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.

  • CVE-2022-39908MedDec 8, 2022
    risk 0.45cvss 6.9epss 0.00

    TOCTOU vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.

  • CVE-2022-39907MedDec 8, 2022
    risk 0.45cvss 6.9epss 0.00

    Integer overflow vulnerability in Samsung decoding library for video thumbnails prior to SMR Dec-2022 Release 1 allows local attacker to perform Out-Of-Bounds Write.

  • CVE-2022-22265MedKEVJan 10, 2022
    risk 0.45cvss 5.0epss 0.00

    An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.

  • CVE-2026-21104MedSep 9, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2026-21097MedSep 9, 2026
    risk 0.44cvss 6.7epss 0.00

    Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.

  • CVE-2026-21085MedSep 9, 2026
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2026-86313HigSep 7, 2026
    risk 0.44cvss 7.8epss 0.00

    Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

  • CVE-2026-47314HigMay 19, 2026
    risk 0.44cvss 7.8epss 0.00

    Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

  • CVE-2026-47311HigMay 19, 2026
    risk 0.44cvss 7.8epss 0.00

    Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

  • CVE-2026-47310HigMay 19, 2026
    risk 0.44cvss 7.8epss 0.00

    Use after free vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

  • CVE-2026-21021MedMay 13, 2026
    risk 0.44cvss 6.8epss 0.00

    Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.

  • CVE-2026-21018MedMay 13, 2026
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2026-21011MedApr 13, 2026
    risk 0.44cvss 6.8epss 0.00

    Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.

Page 16 of 47