VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2026-21009MedApr 13, 2026
    risk 0.44cvss 6.8epss 0.00

    Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.

  • CVE-2026-21007MedApr 13, 2026
    risk 0.44cvss 6.8epss 0.00

    Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.

  • CVE-2026-21003MedApr 13, 2026
    risk 0.44cvss 6.8epss 0.00

    Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions.

  • CVE-2026-20980MedFeb 4, 2026
    risk 0.44cvss 6.8epss 0.00

    Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.

  • CVE-2026-20968MedJan 9, 2026
    risk 0.44cvss 6.7epss 0.00

    Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2025-21073MedNov 5, 2025
    risk 0.44cvss 6.8epss 0.00

    Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attackers to access user data. User interaction is required for triggering this vulnerability.

  • CVE-2025-21048MedOct 10, 2025
    risk 0.44cvss 6.7epss 0.00

    Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2025-21031MedSep 3, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.

  • CVE-2023-21473MedSep 3, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

  • CVE-2023-21472MedSep 3, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.

  • CVE-2025-20984MedJun 4, 2025
    risk 0.44cvss 6.8epss 0.00

    Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to access data in Samsung Cloud for Galaxy Watch.

  • CVE-2025-20937MedMay 7, 2025
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-20897MedFeb 4, 2025
    risk 0.44cvss 6.8epss 0.00

    Improper access control in Secure Folder prior to version 1.9.20.50 in Android 14, 1.8.11.0 in Android 13, and 1.7.04.0 in Android 12 allows local attacker to access data in Secure Folder.

  • CVE-2024-49406MedNov 6, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper validation of integrity check value in Blockchain Keystore prior to version 1.3.16 allows local attackers to modify transaction. Root privilege is required for triggering this vulnerability.

  • CVE-2024-27387MedSep 9, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is no input validation check on rtt_id coming from userspace, which can lead to a heap overwrite.

  • CVE-2024-27383MedSep 9, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_get_scan_extra_ies(), there is no input validation check on default_ies coming from userspace, which can lead to a heap overwrite.

  • CVE-2024-34638MedSep 4, 2024
    risk 0.44cvss 6.7epss 0.00

    Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.

  • CVE-2024-27386MedJul 9, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite.

  • CVE-2024-27385MedJul 9, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for rx coming from userspace, which can lead to heap overwrite.

  • CVE-2024-31958MedJun 7, 2024
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in Samsung Mobile Processor EExynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in an Out-of-Bounds Write.

  • CVE-2024-27379MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead…

  • CVE-2024-27377MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_get_security_info_nl(), there is no input validation check on sec_info->key_info.body.pmk_info.pmk_len coming from userspace, which can…

  • CVE-2024-27376MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->rx_match_filter_len coming from userspace, which can lead to…

  • CVE-2024-27375MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->sdea_service_specific_info_len coming from userspace, which…

  • CVE-2024-27374MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_publish_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead…

  • CVE-2024-27373MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->mesh_id_len coming from userspace, which can lead to a heap…

  • CVE-2024-27372MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->infrastructure_ssid_len coming from userspace, which can lead…

  • CVE-2024-27371MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can…

  • CVE-2024-27370MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on hal_req->num_config_discovery_attr coming from userspace, which can lead…

  • CVE-2024-31953MedMay 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (The attacker must already have user…

  • CVE-2024-31952MedMay 14, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be…

  • CVE-2024-20863MedMay 7, 2024
    risk 0.44cvss 6.7epss 0.00

    Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2024-20838MedMar 5, 2024
    risk 0.44cvss 6.8epss 0.00

    Improper validation vulnerability in Samsung Internet prior to version 24.0.3.2 allows local attackers to execute arbitrary code.

  • CVE-2024-20803MedJan 4, 2024
    risk 0.44cvss 6.8epss 0.00

    Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.

  • CVE-2023-42577MedDec 5, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper Access Control in Samsung Voice Recorder prior to versions 21.4.15.01 in Android 12 and Android 13, 21.4.50.17 in Android 14 allows physical attackers to access Voice Recorder information on the lock screen.

  • CVE-2023-42563MedDec 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.

  • CVE-2023-42562MedDec 5, 2023
    risk 0.44cvss 6.7epss 0.00

    Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.

  • CVE-2023-42530MedNov 7, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control vulnerability in SecSettings prior to SMR Nov-2023 Release 1 allows attackers to enable Wi-Fi and Wi-Fi Direct without User Interaction.

  • CVE-2023-42529MedNov 7, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-42528MedNov 7, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper Input Validation vulnerability in ProcessNvBuffering of libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30739MedNov 7, 2023
    risk 0.44cvss 6.7epss 0.00

    Arbitrary File Descriptor Write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30727MedOct 4, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper access control vulnerability in SecSettings prior to SMR Oct-2023 Release 1 allows attackers to enable Wi-Fi and connect arbitrary Wi-Fi without User Interaction.

  • CVE-2023-30712MedSep 6, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.

  • CVE-2023-40293MedAug 14, 2023
    risk 0.44cvss 6.8epss 0.02

    Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.

  • CVE-2023-40291MedAug 14, 2023
    risk 0.44cvss 6.8epss 0.01

    Harman Infotainment 20190525031613 allows root access via SSH over a USB-to-Ethernet dongle with a password that is an internal project name.

  • CVE-2023-30705MedAug 10, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission.

  • CVE-2023-30702MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Stack overflow vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.

  • CVE-2023-30695MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary…

  • CVE-2023-30694MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in IpcTxPcscTransmitApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30693MedAug 10, 2023
    risk 0.44cvss 6.7epss 0.00

    Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.

Page 17 of 47