VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2026-6839MedApr 22, 2026
    risk 0.36cvss 6.6epss 0.00

    Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE Affected version is prior to commit 1.30.0.

  • CVE-2026-41667MedApr 22, 2026
    risk 0.36cvss 6.6epss 0.00

    Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes. Affected version is prior to commit 1.30.0.

  • CVE-2026-41666MedApr 22, 2026
    risk 0.36cvss 6.6epss 0.00

    Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation. Affected version is prior to commit 1.30.0.

  • CVE-2026-41664MedApr 22, 2026
    risk 0.36cvss 6.6epss 0.00

    Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes. Affected version is prior to commit 1.30.0.

  • CVE-2026-40450MedApr 22, 2026
    risk 0.36cvss 6.6epss 0.00

    Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption for oversized tensors. Affected version is prior to commit 1.30.0.

  • CVE-2026-40449MedApr 22, 2026
    risk 0.36cvss 6.6epss 0.00

    Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source ONE. Affected version is prior to commit 1.30.0.

  • CVE-2026-21013MedApr 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Incorrect default permission in Galaxy Wearable prior to version 2.2.68.26 allows local attackers to access sensitive information.

  • CVE-2026-21002MedMar 16, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper verification of cryptographic signature in Galaxy Store prior to version 4.6.03.8 allows local attacker to install arbitrary application.

  • CVE-2026-21001MedMar 16, 2026
    risk 0.36cvss 5.5epss 0.00

    Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

  • CVE-2026-21000MedMar 16, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.

  • CVE-2026-20993MedMar 16, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper export of android application components in Samsung Assistant prior to version 9.3.10.7 allows local attacker to access saved information.

  • CVE-2025-62816MedMar 3, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, and 2500. Unvalidated VS4L_VERTEXIOC_BOOTUP input leads to a denial of service.

  • CVE-2025-62815MedMar 3, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.ast.thread_ref in set_cpu_affinity() causes a denial of service.

  • CVE-2026-20986MedFeb 4, 2026
    risk 0.36cvss 5.5epss 0.00

    Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members.

  • CVE-2026-20977MedFeb 4, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.

  • CVE-2025-58348MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/confg_tspec write operation,…

  • CVE-2025-58347MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/p2p_certif write operation,…

  • CVE-2025-58346MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_addts write operation,…

  • CVE-2025-58345MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_certif_11ax_mode write…

  • CVE-2025-58343MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/create_tspec write…

  • CVE-2026-20975MedJan 9, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path.

  • CVE-2026-20969MedJan 9, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-58485MedDec 2, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Samsung Internet prior to version 29.0.0.48 allows local attackers to inject arbitrary script.

  • CVE-2025-58475MedDec 2, 2025
    risk 0.36cvss 5.6epss 0.00

    Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21076MedNov 5, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient permissions or privileges in Samsung Account prior to version 15.5.00.18 allows local attackers to access data in Samsung Account. User interaction is required for triggering this vulnerability.

  • CVE-2025-21060MedOct 10, 2025
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. User interaction is required for triggering this vulnerability.

  • CVE-2025-21049MedOct 10, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

  • CVE-2025-21028MedSep 3, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.

  • CVE-2025-21019MedAug 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.

  • CVE-2025-21012MedAug 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in fall detection for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to modify fall detection configuration.

  • CVE-2025-21011MedAug 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in SemSensorService for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to motion and body sensors.

  • CVE-2025-21009MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

  • CVE-2025-21008MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

  • CVE-2025-21007MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

  • CVE-2025-21005MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.

  • CVE-2025-20998MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.

  • CVE-2025-20988MedJun 4, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.

  • CVE-2025-20986MedJun 4, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in ScreenCapture for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to take screenshots.

  • CVE-2025-20985MedJun 4, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items.

  • CVE-2025-20976MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to read out-of-bounds memory.

  • CVE-2025-20975MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper Export of Android Application Components in AODService prior to version 8.8.28.12 allows local attackers to launch arbitrary activity with systemui privilege.

  • CVE-2025-20971MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.

  • CVE-2025-20969MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows local attackers to access data within Samsung Gallery.

  • CVE-2025-20961MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.

  • CVE-2025-20955MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.

  • CVE-2025-20954MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

  • CVE-2025-20952MedApr 9, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.

  • CVE-2025-20948MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.

  • CVE-2025-20947MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.

  • CVE-2025-20938MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.

Page 26 of 47