VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2019-20575MedMar 24, 2020
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019).

  • CVE-2016-1319MedFeb 9, 2016
    risk 0.35cvss 5.3epss 0.01

    Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communications Manager IM & Presence Service 10.5(2); Unified Contact Center Express 11.0(1); and Unity Connection 10.5(2) store a cleartext…

  • CVE-2026-21092MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Path traversal in ImsService prior to SMR Sep-2026 Release 1 allows remote attackers to create image files with system server privilege.

  • CVE-2026-20996MedMar 16, 2026
    risk 0.34cvss 5.3epss 0.00

    Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.

  • CVE-2026-20995MedMar 16, 2026
    risk 0.34cvss 5.3epss 0.00

    Exposure of sensitive functionality to an unauthorized actor in Smart Switch prior to version 3.7.69.15 allows remote attackers to set a specific configuration.

  • CVE-2026-20973MedJan 9, 2026
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.

  • CVE-2025-53965MedDec 3, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to decode the SOR transparent container…

  • CVE-2025-27374MedNov 4, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, 1330, 1380, 1480, 2400. The lack of a length check leads to out-of-bounds writes.

  • CVE-2025-54333MedNov 4, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Invalid Pointer Dereference of node in the get_vs4l_profiler_node function.

  • CVE-2025-54325MedNov 4, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1080, 1280, 2200, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000. A race condition in the VTS driver results in an out-of-bounds read, leading to an information leak.

  • CVE-2025-54331MedNov 4, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function.

  • CVE-2025-54330MedNov 4, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Out-of-bounds Read of q->bufs[] in the __is_done_for_me function.

  • CVE-2025-21047MedOct 10, 2025
    risk 0.34cvss 5.2epss 0.00

    Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.

  • CVE-2023-21479MedSep 3, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.

  • CVE-2023-21466MedSep 3, 2025
    risk 0.34cvss 5.3epss 0.00

    PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.

  • CVE-2025-32098MedSep 2, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.

  • CVE-2025-20989MedJun 4, 2025
    risk 0.34cvss 5.2epss 0.00

    Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key.

  • CVE-2025-20987MedJun 4, 2025
    risk 0.34cvss 5.2epss 0.00

    Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a auth_token.

  • CVE-2025-20891MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

  • CVE-2025-20889MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

  • CVE-2025-20887MedFeb 4, 2025
    risk 0.34cvss 5.3epss 0.00

    Out-of-bounds read in accessing table used for svp8t in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.

  • CVE-2024-46919MedJan 13, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to a stack out-of-bounds write at loadOutputBuffers.

  • CVE-2024-49422MedDec 31, 2024
    risk 0.34cvss 5.2epss 0.00

    Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.

  • CVE-2024-49405MedNov 6, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper authentication in Private Info in Samsung Pass in prior to version 4.4.04.7 allows physical attackers to access sensitive information in a specific scenario.

  • CVE-2024-34663MedOct 8, 2024
    risk 0.34cvss 5.3epss 0.00

    Integer overflow in libSEF.quram.so prior to SMR Oct-2024 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2024-28068MedJul 9, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was discovered in SS in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 2400, Exynos 9110,…

  • CVE-2024-28067MedJul 9, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle (MITM) attacker to downgrade the security mode of packets going to the victim, enabling the attacker to send messages to the victim in plaintext.

  • CVE-2024-34592MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

  • CVE-2024-34591MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

  • CVE-2024-34590MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

  • CVE-2024-34589MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

  • CVE-2024-34588MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation혻in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.

  • CVE-2024-20890MedJul 2, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.

  • CVE-2023-49927MedJun 5, 2024
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123, Exynos Modem 5300. The baseband…

  • CVE-2024-20837MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper handling of granting permission for Trusted Web Activities in Samsung Internet prior to version 24.0.0.41 allows local attackers to grant permission to their own TWA WebApps without user interaction.

  • CVE-2024-20830MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.00

    Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.

  • CVE-2023-37367MedSep 8, 2023
    risk 0.34cvss 5.3epss 0.01

    An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem (Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300, and Exynos Auto T5123. In the NAS…

  • CVE-2023-30700MedAug 10, 2023
    risk 0.34cvss 5.3epss 0.00

    PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.

  • CVE-2023-30666MedJul 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.

  • CVE-2023-30663MedJul 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.

  • CVE-2023-21486MedMay 4, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.

  • CVE-2023-21485MedMay 4, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.

  • CVE-2022-39862MedOct 7, 2022
    risk 0.34cvss 5.3epss 0.01

    Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorized use of javascript interface api.

  • CVE-2022-33715MedAug 5, 2022
    risk 0.34cvss 5.3epss 0.00

    Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local attacker to access files of One UI.

  • CVE-2022-33712MedJul 12, 2022
    risk 0.34cvss 5.3epss 0.01

    Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.

  • CVE-2022-30743MedJun 7, 2022
    risk 0.34cvss 5.3epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.

  • CVE-2022-30736MedJun 7, 2022
    risk 0.34cvss 5.3epss 0.00

    Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows attackers to get the data of contact and gallery without permission.

  • CVE-2022-28779MedApr 11, 2022
    risk 0.34cvss 5.3epss 0.00

    Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code.

  • CVE-2022-26090MedApr 11, 2022
    risk 0.34cvss 5.3epss 0.00

    Improper access control vulnerability in SamsungContacts prior to SMR Apr-2022 Release 1 allows that attackers can access contact information without permission.

  • CVE-2022-25819MedMar 10, 2022
    risk 0.34cvss 5.3epss 0.00

    OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.

Page 30 of 47