VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2024-34609MedAug 7, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

  • CVE-2024-34608MedAug 7, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

  • CVE-2024-34607MedAug 7, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

  • CVE-2024-34606MedAug 7, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

  • CVE-2024-34605MedAug 7, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

  • CVE-2024-34604MedAug 7, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.

  • CVE-2024-31957MedJul 9, 2024
    risk 0.40cvss 6.2epss 0.00

    A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.

  • CVE-2024-20893MedJul 2, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.

  • CVE-2024-20887MedJun 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Arbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory.

  • CVE-2024-20884MedJun 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.

  • CVE-2024-20883MedJun 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.

  • CVE-2024-20876MedJun 4, 2024
    risk 0.40cvss 6.1epss 0.00

    Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.

  • CVE-2024-20872MedMay 7, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.

  • CVE-2024-20850MedApr 2, 2024
    risk 0.40cvss 6.2epss 0.00

    Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay.

  • CVE-2024-20806MedJan 4, 2024
    risk 0.40cvss 6.2epss 0.00

    Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.

  • CVE-2023-42543MedNov 7, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege.

  • CVE-2023-42531MedNov 7, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.

  • CVE-2023-30713MedSep 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.

  • CVE-2020-22181MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.00

    A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi

  • CVE-2023-30677MedJul 6, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass on a certain state of an unlocked device.

  • CVE-2023-30675MedJul 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung Wallet is not installed.

  • CVE-2023-30662MedJul 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

  • CVE-2023-30661MedJul 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

  • CVE-2023-30660MedJul 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.

  • CVE-2023-30659MedJul 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30657MedJul 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30642MedJul 6, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.

  • CVE-2023-21513MedJun 28, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.

  • CVE-2023-21496MedMay 4, 2023
    risk 0.40cvss 6.1epss 0.00

    Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.

  • CVE-2023-21458MedMar 16, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.

  • CVE-2023-21446MedFeb 9, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper input validation in MyFiles prior to version 12.2.09 in Android R(11), 13.1.03.501 in Android S( 12) and 14.1.00.422 in Android T(13) allows local attacker to access data of MyFiles.

  • CVE-2023-21440MedFeb 9, 2023
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.

  • CVE-2022-39912MedDec 8, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.

  • CVE-2022-39890MedNov 9, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.

  • CVE-2022-39846MedSep 9, 2022
    risk 0.40cvss 6.2epss 0.00

    DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.

  • CVE-2022-36837MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.

  • CVE-2022-36836MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.

  • CVE-2022-36831MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.

  • CVE-2022-36830MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

  • CVE-2022-36829MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.

  • CVE-2022-33734MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Sensitive information exposure in onCharacteristicChanged in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.

  • CVE-2022-33733MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Sensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.

  • CVE-2022-33732MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in Samsung Dex for PC prior to SMR Aug-2022 Release 1 allows local attackers to scan and connect to PC by unprotected binder call.

  • CVE-2022-33718MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.

  • CVE-2022-33714MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.

  • CVE-2022-33702MedJul 12, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper authorization vulnerability in Knoxguard prior to SMR Jul-2022 Release 1 allows local attacker to disable keyguard and bypass Knoxguard lock by factory reset.

  • CVE-2022-33691MedJul 12, 2022
    risk 0.40cvss 6.2epss 0.00

    A possible race condition vulnerability in score driver prior to SMR Jul-2022 Release 1 can allow local attackers to interleave malicious operations.

  • CVE-2022-33689MedJul 12, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in TelephonyUI prior to SMR Jul-2022 Release 1 allows attackers to change preferred network type by unprotected binder call.

  • CVE-2022-30744MedJun 7, 2022
    risk 0.40cvss 6.2epss 0.00

    DLL hijacking vulnerability in KiesWrapper in Samsung Kies prior to version 2.6.4.22043_1 allows attacker to execute arbitrary code.

  • CVE-2022-30727MedJun 7, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper handling of insufficient permissions vulnerability in addAppPackageNameToAllowList in PersonaManagerService prior to SMR Jun-2022 Release 1 allows local attackers to set some setting value in work space.

Page 22 of 47