Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-34609 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34608 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34607 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34606 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34605 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34604 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-31957 | Med | 0.40 | 6.2 | 0.00 | Jul 9, 2024 | A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length. | ||
| CVE-2024-20893 | Med | 0.40 | 6.1 | 0.00 | Jul 2, 2024 | Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption. | ||
| CVE-2024-20887 | Med | 0.40 | 6.2 | 0.00 | Jun 4, 2024 | Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory. | ||
| CVE-2024-20884 | Med | 0.40 | 6.2 | 0.00 | Jun 4, 2024 | Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API. | ||
| CVE-2024-20883 | Med | 0.40 | 6.2 | 0.00 | Jun 4, 2024 | Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API. | ||
| CVE-2024-20876 | Med | 0.40 | 6.1 | 0.00 | Jun 4, 2024 | Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption. | ||
| CVE-2024-20872 | Med | 0.40 | 6.2 | 0.00 | May 7, 2024 | Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE. | ||
| CVE-2024-20850 | Med | 0.40 | 6.2 | 0.00 | Apr 2, 2024 | Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay. | ||
| CVE-2024-20806 | Med | 0.40 | 6.2 | 0.00 | Jan 4, 2024 | Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data. | ||
| CVE-2023-42543 | Med | 0.40 | 6.2 | 0.00 | Nov 7, 2023 | Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege. | ||
| CVE-2023-42531 | Med | 0.40 | 6.2 | 0.00 | Nov 7, 2023 | Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background. | ||
| CVE-2023-30713 | Med | 0.40 | 6.2 | 0.00 | Sep 6, 2023 | Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock. | ||
| CVE-2020-22181 | Med | 0.40 | 6.1 | 0.00 | Aug 22, 2023 | A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi | ||
| CVE-2023-30677 | Med | 0.40 | 6.1 | 0.00 | Jul 6, 2023 | Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device. | ||
| CVE-2023-30675 | Med | 0.40 | 6.2 | 0.00 | Jul 6, 2023 | Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed. | ||
| CVE-2023-30662 | Med | 0.40 | 6.2 | 0.00 | Jul 6, 2023 | Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier. | ||
| CVE-2023-30661 | Med | 0.40 | 6.2 | 0.00 | Jul 6, 2023 | Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier. | ||
| CVE-2023-30660 | Med | 0.40 | 6.2 | 0.00 | Jul 6, 2023 | Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier. | ||
| CVE-2023-30659 | Med | 0.40 | 6.2 | 0.00 | Jul 6, 2023 | Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2023-30657 | Med | 0.40 | 6.2 | 0.00 | Jul 6, 2023 | Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2023-30642 | Med | 0.40 | 6.2 | 0.00 | Jul 6, 2023 | Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function. | ||
| CVE-2023-21513 | Med | 0.40 | 6.1 | 0.00 | Jun 28, 2023 | Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition. | ||
| CVE-2023-21496 | Med | 0.40 | 6.1 | 0.00 | May 4, 2023 | Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level. | ||
| CVE-2023-21458 | Med | 0.40 | 6.2 | 0.00 | Mar 16, 2023 | Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent. | ||
| CVE-2023-21446 | Med | 0.40 | 6.2 | 0.00 | Feb 9, 2023 | Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles. | ||
| CVE-2023-21440 | Med | 0.40 | 6.2 | 0.00 | Feb 9, 2023 | Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture. | ||
| CVE-2022-39912 | Med | 0.40 | 6.2 | 0.00 | Dec 8, 2022 | Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder. | ||
| CVE-2022-39890 | Med | 0.40 | 6.2 | 0.00 | Nov 9, 2022 | Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information. | ||
| CVE-2022-39846 | Med | 0.40 | 6.2 | 0.00 | Sep 9, 2022 | DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code. | ||
| CVE-2022-36837 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information. | ||
| CVE-2022-36836 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission. | ||
| CVE-2022-36831 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission. | ||
| CVE-2022-36830 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent. | ||
| CVE-2022-36829 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent. | ||
| CVE-2022-33734 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | Sensitive information exposure in onCharacteristicChanged in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission. | ||
| CVE-2022-33733 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | Sensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission. | ||
| CVE-2022-33732 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call. | ||
| CVE-2022-33718 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data. | ||
| CVE-2022-33714 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot. | ||
| CVE-2022-33702 | Med | 0.40 | 6.2 | 0.00 | Jul 12, 2022 | Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset. | ||
| CVE-2022-33691 | Med | 0.40 | 6.2 | 0.00 | Jul 12, 2022 | A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations. | ||
| CVE-2022-33689 | Med | 0.40 | 6.2 | 0.00 | Jul 12, 2022 | Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call. | ||
| CVE-2022-30744 | Med | 0.40 | 6.2 | 0.00 | Jun 7, 2022 | DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code. | ||
| CVE-2022-30727 | Med | 0.40 | 6.2 | 0.00 | Jun 7, 2022 | Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space. |
- risk 0.40cvss 6.2epss 0.00
Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.
- risk 0.40cvss 6.2epss 0.00
Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory.
- risk 0.40cvss 6.2epss 0.00
Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.
- risk 0.40cvss 6.2epss 0.00
Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.
- risk 0.40cvss 6.2epss 0.00
Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.
- risk 0.40cvss 6.2epss 0.00
Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay.
- risk 0.40cvss 6.2epss 0.00
Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.
- risk 0.40cvss 6.2epss 0.00
Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege.
- risk 0.40cvss 6.2epss 0.00
Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.
- risk 0.40cvss 6.2epss 0.00
Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.
- risk 0.40cvss 6.1epss 0.00
A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi
- risk 0.40cvss 6.1epss 0.00
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.
- risk 0.40cvss 6.2epss 0.00
Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed.
- risk 0.40cvss 6.2epss 0.00
Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
- risk 0.40cvss 6.2epss 0.00
Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
- risk 0.40cvss 6.2epss 0.00
Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
- risk 0.40cvss 6.2epss 0.00
Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.40cvss 6.2epss 0.00
Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.40cvss 6.2epss 0.00
Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.
- risk 0.40cvss 6.1epss 0.00
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
- risk 0.40cvss 6.1epss 0.00
Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.
- risk 0.40cvss 6.2epss 0.00
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
- risk 0.40cvss 6.2epss 0.00
Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles.
- risk 0.40cvss 6.2epss 0.00
Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.
- risk 0.40cvss 6.2epss 0.00
Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.
- risk 0.40cvss 6.2epss 0.00
Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.
- risk 0.40cvss 6.2epss 0.00
DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.
- risk 0.40cvss 6.2epss 0.00
Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.
- risk 0.40cvss 6.2epss 0.00
Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.
- risk 0.40cvss 6.2epss 0.00
Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.
- risk 0.40cvss 6.2epss 0.00
PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
- risk 0.40cvss 6.2epss 0.00
PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
- risk 0.40cvss 6.2epss 0.00
Sensitive information exposure in onCharacteristicChanged in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.
- risk 0.40cvss 6.2epss 0.00
Sensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.
- risk 0.40cvss 6.2epss 0.00
Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.
- risk 0.40cvss 6.2epss 0.00
An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.
- risk 0.40cvss 6.2epss 0.00
Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.
- risk 0.40cvss 6.2epss 0.00
Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.
- risk 0.40cvss 6.2epss 0.00
A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations.
- risk 0.40cvss 6.2epss 0.00
Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.
- risk 0.40cvss 6.2epss 0.00
DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.
- risk 0.40cvss 6.2epss 0.00
Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.
Page 22 of 47