VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2022-30726MedJun 7, 2022
    risk 0.40cvss 6.2epss 0.00

    Unprotected component vulnerability in DeviceSearchTrampoline in SecSettingsIntelligence prior to SMR Jun-2022 Release 1 allows local attackers to launch activities of SecSettingsIntelligence.

  • CVE-2022-30722MedJun 7, 2022
    risk 0.40cvss 6.2epss 0.00

    Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows attackers to bypass user confirmation of Samsung Account.

  • CVE-2022-28792MedMay 3, 2022
    risk 0.40cvss 6.2epss 0.00

    DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper absolute path to prevent dll hijacking.

  • CVE-2022-28791MedMay 3, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.

  • CVE-2022-28789MedMay 3, 2022
    risk 0.40cvss 6.2epss 0.00

    Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper permission for vulnerable activities.

  • CVE-2022-28783MedMay 3, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper validation of removing package name in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to uninstall arbitrary packages without permission. The patch adds proper validation logic for removing package name.

  • CVE-2022-28544MedApr 11, 2022
    risk 0.40cvss 6.2epss 0.01

    Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.

  • CVE-2022-27843MedApr 11, 2022
    risk 0.40cvss 6.2epss 0.00

    DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.

  • CVE-2022-27842MedApr 11, 2022
    risk 0.40cvss 6.2epss 0.00

    DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.

  • CVE-2022-25825MedMar 10, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.

  • CVE-2022-23998MedFeb 11, 2022
    risk 0.40cvss 6.2epss 0.01

    Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(9) allows untrusted applications to take a picture in screenlock status.

  • CVE-2022-22268MedJan 10, 2022
    risk 0.40cvss 6.1epss 0.00

    Incorrect implementation of Knox Guard prior to SMR Jan-2022 Release 1 allows physically proximate attackers to temporary unlock the Knox Guard via Samsung DeX mode.

  • CVE-2021-25512MedDec 8, 2021
    risk 0.40cvss 6.1epss 0.00

    An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.

  • CVE-2021-25382MedApr 23, 2021
    risk 0.40cvss 6.1epss 0.00

    An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorized access to contents in Secure Folder via debugging command.

  • CVE-2021-25344MedMar 4, 2021
    risk 0.40cvss 6.2epss 0.00

    Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to device's serial number without permission.

  • CVE-2020-7811MedOct 12, 2020
    risk 0.40cvss 6.2epss 0.01

    Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication

  • CVE-2018-21068MedApr 8, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.0) software. Execution of an application in a locked Secure Folder can occur without a password via a split screen. The Samsung ID is SVE-2018-11669 (July 2018).

  • CVE-2018-21048MedApr 8, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. There is a Notification leak on a locked device in Standalone Dex mode. The Samsung ID is SVE-2018-12925 (November 2018).

  • CVE-2018-21045MedApr 8, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is Clipboard access in the lockscreen state via a copy-and-paste action. The Samsung ID is SVE-2018-13381 (December 2018).

  • CVE-2019-20569MedMar 24, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via the status bar. The Samsung ID is SVE-2019-15089 (September 2019).

  • CVE-2019-20554MedMar 24, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. Attackers can bypass Factory Reset Protection (FRP) via an external keyboard. The Samsung ID is SVE-2019-15164 (October 2019).

  • CVE-2019-20535MedMar 24, 2020
    risk 0.40cvss 6.2epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. A connection to a new Bluetooth devices can be established from the lock screen. The Samsung ID is SVE-2019-15533 (December 2019).

  • CVE-2019-12315MedMay 24, 2019
    risk 0.40cvss 6.1epss 0.01

    Samsung SCX-824 printers allow a reflected Cross-Site-Scripting (XSS) vulnerability that can be triggered by using the "print from file" feature, as demonstrated by the sws/swsAlert.sws?popupid=successMsg msg parameter.

  • CVE-2019-7421MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.02

    XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.login/gnb/loginView.sws" in multiple parameters: contextpath and basedURL.

  • CVE-2019-7420MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.02

    XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws.application/information/networkinformationView.sws" in the tabName parameter.

  • CVE-2019-7419MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.02

    XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/leftmenu.sws" in multiple parameters: ruiFw_id, ruiFw_pid, ruiFw_title.

  • CVE-2019-7418MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.02

    XSS exists in SAMSUNG X7400GX SyncThru Web Service V6.A6.25 V11.01.05.25_08-21-2015 in "/sws/swsAlert.sws" in multiple parameters: flag, frame, func, and Nfunc.

  • CVE-2018-14904MedAug 3, 2018
    risk 0.40cvss 6.1epss 0.01

    Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as demonstrated by ruiFw_pid.

  • CVE-2018-11689MedJun 14, 2018
    risk 0.40cvss 6.1epss 0.02

    Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)

  • CVE-2018-9140MedMar 30, 2018
    risk 0.40cvss 6.1epss 0.01

    On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.

  • CVE-2017-17859MedDec 27, 2017
    risk 0.40cvss 6.1epss 0.01

    Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part of an MHTML file. Specifically, JavaScript code in another…

  • CVE-2026-20982MedFeb 4, 2026
    risk 0.39cvss 6.0epss 0.00

    Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.

  • CVE-2023-21478MedSep 3, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

  • CVE-2025-21010MedAug 6, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.

  • CVE-2025-20907MedFeb 4, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.

  • CVE-2024-27363MedJul 9, 2024
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was discovered in Samsung Mobile Processor Exynos 850, Exynos 9610, Exynos 980, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, and Exynos W930 where it does not properly check a pointer address, which can lead to a Information disclosure.

  • CVE-2024-27360MedJul 9, 2024
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was discovered in Samsung Mobile Processors Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, and Exynos W930 where they do not properly check length of the data, which can lead to a Denial of Service.

  • CVE-2024-27382MedJun 5, 2024
    risk 0.39cvss 6.0epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame(), there is no input validation check on len coming from userspace, which can lead to a heap over-read.

  • CVE-2024-27381MedJun 5, 2024
    risk 0.39cvss 6.0epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_ut(), there is no input validation check on len coming from userspace, which can lead to a heap over-read.

  • CVE-2024-27380MedJun 5, 2024
    risk 0.39cvss 6.0epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_set_delayed_wakeup_type(), there is no input validation check on a length of ioctl_args->args[i] coming from userspace, which can lead to a…

  • CVE-2024-27378MedJun 5, 2024
    risk 0.39cvss 6.0epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_cert(), there is no input validation check on len coming from userspace, which can lead to a heap over-read.

  • CVE-2024-20862MedMay 7, 2024
    risk 0.39cvss 6.0epss 0.00

    Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2024-20861MedMay 7, 2024
    risk 0.39cvss 6.0epss 0.00

    Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause memory corruption.

  • CVE-2023-42558MedDec 5, 2023
    risk 0.39cvss 6.0epss 0.00

    Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.

  • CVE-2023-21500MedMay 4, 2023
    risk 0.39cvss 6.0epss 0.00

    Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.

  • CVE-2023-21498MedMay 4, 2023
    risk 0.39cvss 6.0epss 0.00

    Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.

  • CVE-2023-21453MedMar 16, 2023
    risk 0.39cvss 6.0epss 0.00

    Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.

  • CVE-2021-25490MedOct 6, 2021
    risk 0.39cvss 6.0epss 0.01

    A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged process.

  • CVE-2021-25469MedOct 6, 2021
    risk 0.39cvss 6.0epss 0.00

    A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitrary code execution.

  • CVE-2015-7890MedFeb 12, 2020
    risk 0.39cvss 5.5epss 0.01

    Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung S6 Edge, allow local users to cause a denial of service (memory corruption) via a large (1) buffer or (2) size parameter.

Page 23 of 47