Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-20996 | Med | 0.33 | 5.0 | 0.00 | Jun 4, 2025 | Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20967 | Med | 0.33 | 5.1 | 0.00 | May 7, 2025 | Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows attackers to read and write arbitrary file with the privilege of Samsung Gallery. | ||
| CVE-2025-20959 | Med | 0.33 | 5.1 | 0.00 | May 7, 2025 | Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2025-20953 | Med | 0.33 | 5.1 | 0.00 | May 7, 2025 | Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN. | ||
| CVE-2025-20949 | Med | 0.33 | 5.1 | 0.00 | May 7, 2025 | Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members. | ||
| CVE-2025-20951 | Med | 0.33 | 5.1 | 0.00 | Apr 8, 2025 | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store. | ||
| CVE-2025-20902 | Med | 0.33 | 5.1 | 0.00 | Feb 4, 2025 | Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege. | ||
| CVE-2025-20893 | Med | 0.33 | 5.1 | 0.00 | Feb 4, 2025 | Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications. | ||
| CVE-2024-49401 | Med | 0.33 | 5.1 | 0.00 | Nov 6, 2024 | Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2024-45185 | Med | 0.33 | 5.1 | 0.00 | Nov 4, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, Modem 5300. There is an out-of-bounds write due to a heap overflow in the GPRS… | ||
| CVE-2024-34648 | Med | 0.33 | 5.1 | 0.00 | Sep 4, 2024 | Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data. | ||
| CVE-2024-34641 | Med | 0.33 | 5.1 | 0.00 | Sep 4, 2024 | Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration. | ||
| CVE-2024-34616 | Med | 0.33 | 5.1 | 0.00 | Aug 7, 2024 | Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data. | ||
| CVE-2024-34615 | Med | 0.33 | 5.1 | 0.00 | Aug 7, 2024 | Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption. | ||
| CVE-2024-34611 | Med | 0.33 | 5.1 | 0.00 | Aug 7, 2024 | Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-34610 | Med | 0.33 | 5.1 | 0.00 | Aug 7, 2024 | Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data. | ||
| CVE-2024-27361 | Med | 0.33 | 5.1 | 0.00 | Jul 9, 2024 | A vulnerability was discovered in Samsung Mobile Processor Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, and Exynos 2400 that involves a time-of-check to time-of-use (TOCTOU) race condition, which can lead to a Denial of Service. | ||
| CVE-2024-20885 | Med | 0.33 | 5.1 | 0.00 | Jun 4, 2024 | Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission. | ||
| CVE-2024-20870 | Med | 0.33 | 5.1 | 0.00 | May 7, 2024 | Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store. | ||
| CVE-2024-20853 | Med | 0.33 | 5.1 | 0.00 | Apr 2, 2024 | Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrary files to sandbox of ThemeStore. | ||
| CVE-2024-20841 | Med | 0.33 | 5.1 | 0.00 | Mar 5, 2024 | Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data. | ||
| CVE-2024-20811 | Med | 0.33 | 5.1 | 0.00 | Feb 6, 2024 | Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer. | ||
| CVE-2023-42574 | Med | 0.33 | 5.1 | 0.00 | Dec 5, 2023 | Improper access control vulnerablility in GameHomeCN prior to version 4.2.60.2 allows local attackers to launch arbitrary activity in GameHomeCN. | ||
| CVE-2023-30735 | Med | 0.33 | 5.1 | 0.00 | Oct 4, 2023 | Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant. | ||
| CVE-2023-30725 | Med | 0.33 | 5.1 | 0.00 | Sep 6, 2023 | Improper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in content provider. | ||
| CVE-2023-30678 | Med | 0.33 | 5.1 | 0.00 | Jul 6, 2023 | Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file. | ||
| CVE-2023-30667 | Med | 0.33 | 5.1 | 0.00 | Jul 6, 2023 | Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege. | ||
| CVE-2023-21487 | Med | 0.33 | 5.1 | 0.00 | May 4, 2023 | Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting. | ||
| CVE-2023-21484 | Med | 0.33 | 5.1 | 0.00 | May 4, 2023 | Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation. | ||
| CVE-2023-21459 | Med | 0.33 | 5.0 | 0.00 | Mar 16, 2023 | Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault. | ||
| CVE-2023-21424 | Med | 0.33 | 5.1 | 0.00 | Feb 9, 2023 | Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand. | ||
| CVE-2023-21423 | Med | 0.33 | 5.1 | 0.00 | Feb 9, 2023 | Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action. | ||
| CVE-2022-39875 | Med | 0.33 | 5.1 | 0.00 | Oct 7, 2022 | Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout. | ||
| CVE-2022-39855 | Med | 0.33 | 5.1 | 0.00 | Oct 7, 2022 | Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices. | ||
| CVE-2022-36872 | Med | 0.33 | 5.0 | 0.00 | Sep 9, 2022 | Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent. | ||
| CVE-2022-36871 | Med | 0.33 | 5.0 | 0.00 | Sep 9, 2022 | Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent. | ||
| CVE-2022-36870 | Med | 0.33 | 5.0 | 0.00 | Sep 9, 2022 | Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent. | ||
| CVE-2022-36848 | Med | 0.33 | 5.1 | 0.00 | Sep 9, 2022 | Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service. | ||
| CVE-2022-33731 | Med | 0.33 | 5.1 | 0.00 | Aug 5, 2022 | Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components. | ||
| CVE-2022-33695 | Med | 0.33 | 5.1 | 0.00 | Jul 12, 2022 | Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service. | ||
| CVE-2022-30731 | Med | 0.33 | 5.1 | 0.00 | Jun 7, 2022 | Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application. | ||
| CVE-2022-28780 | Med | 0.33 | 5.0 | 0.00 | May 3, 2022 | Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information. | ||
| CVE-2022-28775 | Med | 0.33 | 5.1 | 0.00 | Apr 11, 2022 | Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission. | ||
| CVE-2021-25503 | Med | 0.33 | 5.0 | 0.00 | Nov 5, 2021 | Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution. | ||
| CVE-2021-25489 | Low | 0.33 | 3.3 | 0.01 | KEV | Oct 6, 2021 | Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic. | |
| CVE-2021-25453 | Med | 0.33 | 5.1 | 0.00 | Sep 9, 2021 | Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information. | ||
| CVE-2021-25340 | Med | 0.33 | 5.1 | 0.00 | Mar 4, 2021 | Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State. | ||
| CVE-2025-53079 | Med | 0.32 | 4.9 | 0.00 | Jul 29, 2025 | Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files | ||
| CVE-2025-20995 | Med | 0.32 | 4.9 | 0.00 | Jun 4, 2025 | Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and write arbitrary files. | ||
| CVE-2024-31955 | Med | 0.32 | 4.9 | 0.00 | Oct 15, 2024 | An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possessing secret information. |
- risk 0.33cvss 5.0epss 0.00
Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability.
- risk 0.33cvss 5.1epss 0.00
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows attackers to read and write arbitrary file with the privilege of Samsung Gallery.
- risk 0.33cvss 5.1epss 0.00
Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.33cvss 5.1epss 0.00
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.
- risk 0.33cvss 5.1epss 0.00
Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members.
- risk 0.33cvss 5.1epss 0.00
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
- risk 0.33cvss 5.1epss 0.00
Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege.
- risk 0.33cvss 5.1epss 0.00
Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications.
- risk 0.33cvss 5.1epss 0.00
Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities.
- risk 0.33cvss 5.1epss 0.00
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, Modem 5300. There is an out-of-bounds write due to a heap overflow in the GPRS…
- risk 0.33cvss 5.1epss 0.00
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.
- risk 0.33cvss 5.1epss 0.00
Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.
- risk 0.33cvss 5.1epss 0.00
Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.
- risk 0.33cvss 5.1epss 0.00
Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.
- risk 0.33cvss 5.1epss 0.00
Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.33cvss 5.1epss 0.00
Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.
- risk 0.33cvss 5.1epss 0.00
A vulnerability was discovered in Samsung Mobile Processor Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, and Exynos 2400 that involves a time-of-check to time-of-use (TOCTOU) race condition, which can lead to a Denial of Service.
- risk 0.33cvss 5.1epss 0.00
Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.
- risk 0.33cvss 5.1epss 0.00
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
- risk 0.33cvss 5.1epss 0.00
Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrary files to sandbox of ThemeStore.
- risk 0.33cvss 5.1epss 0.00
Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.
- risk 0.33cvss 5.1epss 0.00
Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.
- risk 0.33cvss 5.1epss 0.00
Improper access control vulnerablility in GameHomeCN prior to version 4.2.60.2 allows local attackers to launch arbitrary activity in GameHomeCN.
- risk 0.33cvss 5.1epss 0.00
Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant.
- risk 0.33cvss 5.1epss 0.00
Improper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in content provider.
- risk 0.33cvss 5.1epss 0.00
Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.
- risk 0.33cvss 5.1epss 0.00
Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.
- risk 0.33cvss 5.1epss 0.00
Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.
- risk 0.33cvss 5.1epss 0.00
Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.
- risk 0.33cvss 5.0epss 0.00
Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.
- risk 0.33cvss 5.1epss 0.00
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.
- risk 0.33cvss 5.1epss 0.00
Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.
- risk 0.33cvss 5.1epss 0.00
Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.
- risk 0.33cvss 5.1epss 0.00
Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.
- risk 0.33cvss 5.0epss 0.00
Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
- risk 0.33cvss 5.0epss 0.00
Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
- risk 0.33cvss 5.0epss 0.00
Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.
- risk 0.33cvss 5.1epss 0.00
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.
- risk 0.33cvss 5.1epss 0.00
Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.
- risk 0.33cvss 5.1epss 0.00
Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.
- risk 0.33cvss 5.1epss 0.00
Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application.
- risk 0.33cvss 5.0epss 0.00
Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.
- risk 0.33cvss 5.1epss 0.00
Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission.
- risk 0.33cvss 5.0epss 0.00
Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.
- risk 0.33cvss 3.3epss 0.01
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
- risk 0.33cvss 5.1epss 0.00
Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.
- risk 0.33cvss 5.1epss 0.00
Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.
- risk 0.32cvss 4.9epss 0.00
Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files
- risk 0.32cvss 4.9epss 0.00
Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and write arbitrary files.
- risk 0.32cvss 4.9epss 0.00
An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possessing secret information.
Page 32 of 47