VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2024-20892MedJul 2, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.

  • CVE-2024-20881MedJun 4, 2024
    risk 0.42cvss 6.4epss 0.00

    Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local privileged attackers lead to potential arbitrary code execution.

  • CVE-2024-20880MedJun 4, 2024
    risk 0.42cvss 6.4epss 0.00

    Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.

  • CVE-2024-20832MedMar 5, 2024
    risk 0.42cvss 6.4epss 0.00

    Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2024-20831MedMar 5, 2024
    risk 0.42cvss 6.4epss 0.00

    Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2023-42579MedDec 5, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data…

  • CVE-2023-42578MedDec 5, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.

  • CVE-2023-30674MedJul 6, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper configuration in Samsung Internet prior to version 21.0.0.41 allows attacker to bypass SameSite Cookie.

  • CVE-2022-39902MedDec 8, 2022
    risk 0.42cvss 6.5epss 0.01

    Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to get sensitive information including IMEI via emergency call.

  • CVE-2022-39901MedDec 8, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.

  • CVE-2022-39854MedOct 7, 2022
    risk 0.42cvss 6.4epss 0.00

    Improper protection in IOMMU prior to SMR Oct-2022 Release 1 allows unauthorized access to secure memory.

  • CVE-2022-40279HigSep 29, 2022
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/src/l2_packet/l2_packet_pcap.c has a missing check on the return value of pcap_dispatch, leading to a denial of service (malfunction).

  • CVE-2022-25818MedMar 10, 2022
    risk 0.42cvss 6.5epss 0.00

    Improper boundary check in UWB stack prior to SMR Mar-2022 Release 1 allows arbitrary code execution.

  • CVE-2022-23432MedFeb 11, 2022
    risk 0.42cvss 6.4epss 0.00

    An improper input validation in SMC_SRPMB_WSM handler of RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

  • CVE-2022-23431MedFeb 11, 2022
    risk 0.42cvss 6.4epss 0.00

    An improper boundary check in RPMB ldfw prior to SMR Feb-2022 Release 1 allows arbitrary memory write and code execution.

  • CVE-2022-22290MedJan 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.

  • CVE-2020-9061MedJan 10, 2022
    risk 0.42cvss 6.5epss 0.01

    Z-Wave devices using Silicon Labs 500 and 700 series chipsets, including but not likely limited to the SiLabs UZB-7 version 7.00, ZooZ ZST10 version 6.04, Aeon Labs ZW090-A version 3.95, and Samsung STH-ETH-200 version 6.04, are susceptible to denial of service via malformed…

  • CVE-2021-25518MedDec 8, 2021
    risk 0.42cvss 6.4epss 0.00

    An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-25516MedDec 8, 2021
    risk 0.42cvss 6.4epss 0.00

    An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.

  • CVE-2021-25481MedOct 6, 2021
    risk 0.42cvss 6.4epss 0.00

    An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of Exynos CP Memory.

  • CVE-2021-25466MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper scheme check vulnerability in Samsung Internet prior to version 15.0.2.47 allows attackers to perform Man-in-the-middle attack and obtain Samsung Account token.

  • CVE-2021-25449MedSep 9, 2021
    risk 0.42cvss 6.5epss 0.00

    An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor process.

  • CVE-2021-25427MedJul 8, 2021
    risk 0.42cvss 6.5epss 0.00

    SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device information

  • CVE-2021-25419MedJun 11, 2021
    risk 0.42cvss 6.5epss 0.01

    Non-compliance of recommended secure coding scheme in Samsung Internet prior to version 14.0.1.62 allows attackers to display fake URL in address bar via phising URL link.

  • CVE-2021-25416MedJun 11, 2021
    risk 0.42cvss 6.5epss 0.00

    Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.

  • CVE-2021-25406MedJun 11, 2021
    risk 0.42cvss 6.5epss 0.00

    Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device information.

  • CVE-2021-25375MedApr 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment.

  • CVE-2018-21092MedApr 8, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.x) and N(7.x) software. A crafted AT command may be sent by the DeviceTest application via an NFC tag. The Samsung ID is SVE-2017-10885 (January 2018).

  • CVE-2017-18695MedApr 7, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) can discover a user's credentials, during an email account login, via an EAS autodiscover packet. The Samsung ID is SVE-2016-7654…

  • CVE-2016-11034MedApr 7, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Qt 5.7 allows attackers to trigger a system crash via a malformed image. The Samsung ID is SVE-2016-6560 (October 2016).

  • CVE-2019-20609MedMar 24, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can use Smartwatch to view Secure Folder notification content. The Samsung ID is SVE-2019-13899 (April 2019).

  • CVE-2019-20546MedMar 24, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom Wi-Fi chipsets) software. A denial-of-service attack can leverage a shared interface between Broadcom Bluetooth and Broadcom Wi-Fi. The Samsung ID is SVE-2019-15350 (November 2019).

  • CVE-2020-10845MedMar 24, 2020
    risk 0.42cvss 6.4epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is a race condition leading to a use-after-free in MTP. The Samsung ID is SVE-2019-16520 (February 2020).

  • CVE-2020-10844MedMar 24, 2020
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.x), and Q(10.0) software. There is an out-of-bounds read vulnerability in media.audio_policy. The Samsung ID is SVE-2019-16333 (February 2020).

  • CVE-2018-16271MedJan 22, 2020
    risk 0.42cvss 6.5epss 0.01

    The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the…

  • CVE-2018-16264MedJan 22, 2020
    risk 0.42cvss 6.5epss 0.01

    The BlueZ system service in Tizen allows an unprivileged process to partially control Bluetooth or acquire sensitive information, due to improper D-Bus security policy configurations. This affects Tizen before 5.0 M1, and Tizen-based firmwares including Samsung Galaxy Gear…

  • CVE-2019-16401MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.01

    Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build Number: JSS15J.I9300XXUGND5, Baseband Vendor: Samsung Exynos 4412, Baseband:…

  • CVE-2019-16400MedNov 6, 2019
    risk 0.42cvss 6.5epss 0.00

    Samsung Galaxy S8 plus (Android version: 8.0.0, Build Number: R16NW.G955USQU5CRG3, Baseband Vendor: Qualcomm Snapdragon 835, Baseband: G955USQU5CRG3), Samsung Galaxy S3 (Android version: 4.3, Build Number: JSS15J.I9300XXUGND5, Baseband Vendor: Samsung Exynos 4412, Baseband:…

  • CVE-2015-8780MedApr 13, 2017
    risk 0.42cvss 6.4epss 0.01

    Samsung wssyncmlnps before 2015-10-31 allows directory traversal in a Kies restore, aka ZipFury.

  • CVE-2016-1308MedFeb 7, 2016
    risk 0.42cvss 6.5epss 0.01

    SQL injection vulnerability in Cisco Unified Communications Manager 10.5(2.13900.9) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCux99227.

  • CVE-2026-21036MedJun 5, 2026
    risk 0.41cvss —epss 0.00

    Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.

  • CVE-2026-21024MedMay 13, 2026
    risk 0.41cvss —epss 0.00

    Improper privilege management in Samsung System Support Service prior to version 8.0.8.0 allows local attackers to trigger privileged functions.

  • CVE-2026-25207HigApr 13, 2026
    risk 0.41cvss 7.4epss 0.00

    Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.

  • CVE-2026-25205HigApr 13, 2026
    risk 0.41cvss 7.4epss 0.00

    Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows out-of-bounds write.This issue affects Escargot:commit hash  97e8115ab1110bc502b4b5e4a0c689a71520d335 .

  • CVE-2023-21474MedSep 3, 2025
    risk 0.41cvss 6.3epss 0.00

    Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.

  • CVE-2025-21017MedAug 6, 2025
    risk 0.41cvss 6.3epss 0.00

    Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-20905MedFeb 4, 2025
    risk 0.41cvss 6.3epss 0.00

    Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.

  • CVE-2025-20904MedFeb 4, 2025
    risk 0.41cvss 6.3epss 0.00

    Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.

  • CVE-2025-20900MedFeb 4, 2025
    risk 0.41cvss 6.3epss 0.00

    Out-of-bounds write in Blockchain Keystore prior to version 1.3.16.5 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2024-36071MedJun 20, 2024
    risk 0.41cvss 6.3epss 0.00

    Samsung Magician 8.0.0 on Windows allows an admin to escalate privileges by tampering with the directory and DLL files used during the installation process. This occurs because of an Untrusted Search Path.

Page 20 of 47