VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2023-42483MedDec 13, 2023
    risk 0.41cvss 6.3epss 0.00

    A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.

  • CVE-2023-42555MedNov 7, 2023
    risk 0.41cvss 6.3epss 0.00

    Use of implicit intent for sensitive communication vulnerability in EasySetup prior to version 11.1.13 allows attackers to get the bluetooth address of user device.

  • CVE-2023-42534MedNov 7, 2023
    risk 0.41cvss 6.3epss 0.00

    Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.

  • CVE-2023-30671MedJul 6, 2023
    risk 0.41cvss 6.3epss 0.00

    Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.

  • CVE-2023-21492MedKEVMay 4, 2023
    risk 0.41cvss 4.4epss 0.03

    Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.

  • CVE-2023-21434MedFeb 9, 2023
    risk 0.41cvss 6.2epss 0.13

    Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.

  • CVE-2021-25511MedDec 8, 2021
    risk 0.41cvss 6.3epss 0.00

    An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.

  • CVE-2021-25337MedKEVMar 4, 2021
    risk 0.41cvss 4.4epss 0.03

    Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.

  • CVE-2018-14856MedDec 17, 2018
    risk 0.41cvss 6.3epss 0.01

    Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi) chip to cause the device driver to…

  • CVE-2018-14855MedDec 17, 2018
    risk 0.41cvss 6.3epss 0.01

    Buffer overflow in dhd_bus_flow_ring_flush_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 allow an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device driver to perform invalid memory…

  • CVE-2018-14854MedDec 17, 2018
    risk 0.41cvss 6.3epss 0.01

    Buffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device driver to…

  • CVE-2018-14852MedDec 17, 2018
    risk 0.41cvss 6.3epss 0.01

    Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause invalid accesses to operating…

  • CVE-2026-21103MedSep 9, 2026
    risk 0.40cvss 6.1epss 0.00

    Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.

  • CVE-2026-21073MedAug 10, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.

  • CVE-2026-21063MedAug 10, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.

  • CVE-2026-20994MedMar 16, 2026
    risk 0.40cvss 6.1epss 0.00

    URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.

  • CVE-2026-20978MedFeb 4, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.

  • CVE-2025-58344MedFeb 3, 2026
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation in a /proc/driver/unifi0/conn_log_event_burst_to_us write operation,…

  • CVE-2025-58342MedFeb 3, 2026
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/uapsd write operation,…

  • CVE-2025-58341MedFeb 3, 2026
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_cert_disable_ht_vht write…

  • CVE-2025-58340MedFeb 3, 2026
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_delts write operation,…

  • CVE-2025-52516MedJan 5, 2026
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of service.

  • CVE-2025-21080MedDec 2, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.

  • CVE-2025-21059MedOct 10, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

  • CVE-2025-21041MedSep 3, 2025
    risk 0.40cvss 6.2epss 0.00

    Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.

  • CVE-2023-21482MedSep 3, 2025
    risk 0.40cvss 6.1epss 0.00

    Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to install package through Galaxy store before completion of Setup wizard.

  • CVE-2025-21013MedAug 6, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time.

  • CVE-2025-53082MedJul 29, 2025
    risk 0.40cvss 6.1epss 0.00

    An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.

  • CVE-2025-21004MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.

  • CVE-2025-21002MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.

  • CVE-2025-21001MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.

  • CVE-2025-21000MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.

  • CVE-2025-20997MedJul 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.

  • CVE-2025-20981MedJun 4, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-20978MedMay 7, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.

  • CVE-2025-20974MedMay 7, 2025
    risk 0.40cvss 6.1epss 0.00

    Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation.

  • CVE-2025-20972MedMay 7, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.

  • CVE-2025-20970MedMay 7, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to access image files with Bixby Vision privilege.

  • CVE-2025-20965MedMay 7, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.

  • CVE-2025-20944MedApr 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.

  • CVE-2025-20941MedApr 8, 2025
    risk 0.40cvss 6.2epss 0.00

    Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.

  • CVE-2025-20912MedMar 6, 2025
    risk 0.40cvss 6.2epss 0.00

    Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.

  • CVE-2025-20910MedMar 6, 2025
    risk 0.40cvss 6.2epss 0.00

    Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.

  • CVE-2024-45184MedOct 11, 2024
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, and Modem 5300. A USAT out-of-bounds write due to a heap buffer…

  • CVE-2024-34662MedOct 8, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors.

  • CVE-2024-34655MedSep 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.

  • CVE-2024-34654MedSep 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.

  • CVE-2024-34651MedSep 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

  • CVE-2024-34645MedSep 4, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.

  • CVE-2024-34637MedSep 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.

Page 21 of 47