VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2024-20865MedMay 7, 2024
    risk 0.43cvss 6.6epss 0.00

    Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.

  • CVE-2024-20819MedFeb 6, 2024
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

  • CVE-2024-20818MedFeb 6, 2024
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

  • CVE-2024-20817MedFeb 6, 2024
    risk 0.43cvss 6.6epss 0.00

    Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

  • CVE-2023-42564MedDec 5, 2023
    risk 0.43cvss 6.6epss 0.00

    Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.

  • CVE-2023-42533MedNov 7, 2023
    risk 0.43cvss 6.6epss 0.00

    Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.

  • CVE-2022-36875MedSep 9, 2022
    risk 0.43cvss 6.6epss 0.00

    Improper restriction of broadcasting Intent in SaWebViewRelayActivity of?Waterplugin prior to version 2.2.11.22081151 allows attacker to access the file without permission.

  • CVE-2022-36869MedSep 9, 2022
    risk 0.43cvss 6.6epss 0.00

    Improper access control vulnerability in ContactsDumpActivity of?Contacts Provider prior to version 12.7.59 allows attacker to access the file without permission.

  • CVE-2022-27822MedApr 11, 2022
    risk 0.43cvss 6.6epss 0.00

    Information exposure vulnerability in ril property setting prior to SMR April-2022 Release 1 allows access to EF_RUIMID value without permission.

  • CVE-2021-25393MedJun 11, 2021
    risk 0.43cvss 6.6epss 0.00

    Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.

  • CVE-2020-26145MedMay 11, 2021
    risk 0.43cvss 6.5epss 0.04

    An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcast fragments even when sent in plaintext and process them as full unfragmented frames. An adversary can abuse this to inject…

  • CVE-2020-26144MedMay 11, 2021
    risk 0.43cvss 6.5epss 0.05

    An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long as the first 8 bytes correspond to a valid RFC1042 (i.e., LLC/SNAP) header for EAPOL. An adversary can abuse this to inject…

  • CVE-2013-7447MedFeb 17, 2016
    risk 0.43cvss 6.5epss 0.05

    Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, allows remote attackers to cause a denial of service (crash) via a large image…

  • CVE-2026-21083MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

  • CVE-2026-21080MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

  • CVE-2026-21079MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.

  • CVE-2026-21078MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Insufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to spoof device identity.

  • CVE-2026-21061MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.

  • CVE-2026-18772MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.

  • CVE-2026-21035MedJun 5, 2026
    risk 0.42cvss —epss 0.00

    Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.

  • CVE-2026-21008MedApr 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.

  • CVE-2026-21005MedMar 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.

  • CVE-2026-21004MedMar 16, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.

  • CVE-2025-54335MedNov 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the Xclipse GPU Driver.

  • CVE-2025-54327MedNov 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W1000. Improper input validation in the VTS driver leads to an arbitrary write.

  • CVE-2023-21483MedSep 3, 2025
    risk 0.42cvss 6.4epss 0.00

    Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.

  • CVE-2025-32100MedSep 2, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. A programming mistake for buffer copy leads to…

  • CVE-2024-45183MedAug 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leads to an out-of-bound write.

  • CVE-2025-53081MedJul 29, 2025
    risk 0.42cvss 6.4epss 0.00

    An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.

  • CVE-2025-53077MedJul 29, 2025
    risk 0.42cvss 6.5epss 0.00

    An execution after redirect in Samsung DMS(Data Management Server) allows attackers to execute limited functions without permissions. An attacker could compromise the integrity of the platform by executing this vulnerability.

  • CVE-2025-20983MedJul 8, 2025
    risk 0.42cvss 6.4epss 0.00

    Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-20982MedJul 8, 2025
    risk 0.42cvss 6.4epss 0.00

    Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-23106MedJun 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.

  • CVE-2025-23101MedJun 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1380. A Use-After-Free in the mobile processor leads to privilege escalation.

  • CVE-2025-23096MedJun 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.

  • CVE-2025-23095MedJun 4, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400. A Double Free in the mobile processor leads to privilege escalation.

  • CVE-2025-23104MedJun 2, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2200. A Use-After-Free in the mobile processor leads to privilege escalation.

  • CVE-2024-49197MedMay 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Wi-Fi in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, W920, W930, and W1000. Lack of a boundary check in STOP_KEEP_ALIVE_OFFLOAD leads to out-of-bounds access.

  • CVE-2025-22377MedMay 27, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. A Heap-based Out-of-Bounds Write exists in the GPRS protocol…

  • CVE-2025-3885MedMay 22, 2025
    risk 0.42cvss 6.5epss 0.00

    Harman Becker MGU21 Bluetooth Improper Input Validation Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Harman Becker MGU21 devices. Authentication is not required to…

  • CVE-2024-56427MedMay 14, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds access via malformed…

  • CVE-2025-26784MedMay 14, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, W920, W930, W1000, Modem 5123, Modem 5300, Modem 5400. The lack of a length check leads to out-of-bounds writes.

  • CVE-2025-20943MedApr 8, 2025
    risk 0.42cvss 6.4epss 0.00

    Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.

  • CVE-2025-20908MedMar 6, 2025
    risk 0.42cvss 6.5epss 0.00

    Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.

  • CVE-2025-20885MedFeb 4, 2025
    risk 0.42cvss 6.4epss 0.00

    Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memory corruption.

  • CVE-2024-46921MedJan 13, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400. UE does not limit the number of attempts for the RRC Setup procedure in the 5G SA, leading…

  • CVE-2024-46920MedJan 13, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to a stack out-of-bounds write at loadInputBuffers.

  • CVE-2024-49418MedDec 3, 2024
    risk 0.42cvss 6.5epss 0.00

    Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to enable JavaScript in its webview.

  • CVE-2024-49409MedNov 6, 2024
    risk 0.42cvss 6.4epss 0.00

    Out-of-bounds write in Battery Full Capacity node prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.

  • CVE-2024-49408MedNov 6, 2024
    risk 0.42cvss 6.4epss 0.00

    Out-of-bounds write in usb driver prior to Firmware update Sep-2024 Release on Galaxy S24 allows local attackers to write out-of-bounds memory. System privilege is required for triggering this vulnerability.

Page 19 of 47