VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2022-27567MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_hvcC function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attackers.

  • CVE-2022-26099MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.

  • CVE-2022-26097MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_unknown_property function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

  • CVE-2022-26096MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

  • CVE-2022-26095MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

  • CVE-2022-26094MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

  • CVE-2022-26093MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_irot function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

  • CVE-2022-24928MedMar 10, 2022
    risk 0.38cvss 5.9epss 0.00

    Security misconfiguration of RKP in kernel prior to SMR Mar-2022 Release 1 allows a system not to be protected by RKP.

  • CVE-2021-25520MedDec 8, 2021
    risk 0.38cvss 5.9epss 0.00

    Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to execute script codes in Samsung Internet.

  • CVE-2021-25509MedNov 5, 2021
    risk 0.38cvss 5.9epss 0.00

    A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows known folders.

  • CVE-2021-25482MedOct 6, 2021
    risk 0.38cvss 5.9epss 0.00

    SQL injection vulnerabilities in CMFA framework prior to SMR Oct-2021 Release 1 allow untrusted application to overwrite some CMFA framework information.

  • CVE-2021-25457MedSep 9, 2021
    risk 0.38cvss 5.9epss 0.00

    An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory information.

  • CVE-2021-25380MedApr 9, 2021
    risk 0.38cvss 5.8epss 0.01

    Improper handling of exceptional conditions in Bixby prior to version 3.0.53.02 allows attacker to execute the actions registered by the user.

  • CVE-2021-25365MedApr 9, 2021
    risk 0.38cvss 5.9epss 0.00

    An improper exception control in softsimd prior to SMR APR-2021 Release 1 allows unprivileged applications to access the API in softsimd.

  • CVE-2018-10751MedMay 29, 2018
    risk 0.38cvss 5.3epss 0.09

    A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.

  • CVE-2018-6019MedMar 6, 2018
    risk 0.38cvss 5.9epss 0.00

    Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption during information transmission.

  • CVE-2017-10963MedFeb 20, 2018
    risk 0.38cvss 5.9epss 0.01

    In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung…

  • CVE-2017-8851MedMay 11, 2017
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both products use the same OTA verification keys, and the fact that both products share the same 'ro.build.product' system property, attackers…

  • CVE-2016-1346MedApr 6, 2016
    risk 0.38cvss 5.9epss 0.02

    The kernel in Cisco TelePresence Server 3.0 through 4.2(4.18) on Mobility Services Engine (MSE) 8710 devices allows remote attackers to cause a denial of service (panic and reboot) via a crafted sequence of IPv6 packets, aka Bug ID CSCuu46673.

  • CVE-2026-25206MedApr 13, 2026
    risk 0.37cvss 6.7epss 0.00

    Out-of-bounds read vulnerability in Samsung Open Source Escargot allows Resource Leak Exposure.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.

  • CVE-2025-21072MedDec 2, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21071MedNov 5, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21044MedOct 10, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21021MedAug 6, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21020MedAug 6, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2024-20866MedMay 7, 2024
    risk 0.37cvss 5.7epss 0.00

    Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.

  • CVE-2024-20840MedMar 5, 2024
    risk 0.37cvss 5.7epss 0.00

    Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers using hardware keyboard to use VoiceRecorder on the lock screen.

  • CVE-2023-30731MedOct 4, 2023
    risk 0.37cvss 5.7epss 0.00

    Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.

  • CVE-2023-21502MedMay 4, 2023
    risk 0.37cvss 5.7epss 0.00

    Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands.

  • CVE-2023-21448MedFeb 9, 2023
    risk 0.37cvss 5.7epss 0.00

    Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file.

  • CVE-2023-21422MedFeb 9, 2023
    risk 0.37cvss 5.7epss 0.00

    Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.

  • CVE-2022-39899MedDec 8, 2022
    risk 0.37cvss 5.7epss 0.00

    Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.

  • CVE-2022-36859MedSep 9, 2022
    risk 0.37cvss 5.7epss 0.00

    Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.21-6 allows privileged attackers to trigger a XSS on a victim's devices.

  • CVE-2022-26091MedApr 11, 2022
    risk 0.37cvss 5.7epss 0.00

    Improper access control vulnerability in Knox Manage prior to SMR Apr-2022 Release 1 allows that physical attackers can bypass Knox Manage using a function key of hardware keyboard.

  • CVE-2022-24926MedFeb 11, 2022
    risk 0.37cvss 5.7epss 0.00

    Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's devices.

  • CVE-2022-22284MedJan 10, 2022
    risk 0.37cvss 5.7epss 0.00

    Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication

  • CVE-2021-25507MedNov 5, 2021
    risk 0.37cvss 5.7epss 0.00

    Improper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with user device to access part of notification data in Secure Folder without authorization.

  • CVE-2021-25501MedNov 5, 2021
    risk 0.37cvss 5.7epss 0.00

    An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.

  • CVE-2017-17860MedJan 18, 2018
    risk 0.37cvss 5.7epss 0.00

    In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user's intention only if attacker can reveal the Bluetooth address of target device and paired user's smartphone

  • CVE-2026-21099MedSep 9, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.

  • CVE-2026-21064MedAug 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.

  • CVE-2026-21028MedJun 5, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

  • CVE-2026-21026MedJun 5, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.

  • CVE-2026-21025MedJun 5, 2026
    risk 0.36cvss 5.5epss 0.00

    Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

  • CVE-2026-21017MedJun 5, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.

  • CVE-2026-21022MedMay 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.

  • CVE-2026-21016MedMay 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.

  • CVE-2026-21015MedMay 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.

  • CVE-2026-3291MedMay 6, 2026
    risk 0.36cvss 5.5epss 0.00

    Samsung Print Service Plugin for Android is potentially vulnerable to information disclosure when using an outdated version of the application via mobile devices. HP is releasing updates to mitigate these potential vulnerabilities.

  • CVE-2026-21023MedApr 29, 2026
    risk 0.36cvss 5.5epss 0.00

    Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.

Page 25 of 47