VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2025-20996MedJun 4, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper authorization in Smart Switch installed on non-Samsung Device prior to version 3.7.64.10 allows local attackers to read data with the privilege of Smart Switch. User interaction is required for triggering this vulnerability.

  • CVE-2025-20967MedMay 7, 2025
    risk 0.33cvss 5.1epss 0.00

    Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows attackers to read and write arbitrary file with the privilege of Samsung Gallery.

  • CVE-2025-20959MedMay 7, 2025
    risk 0.33cvss 5.1epss 0.00

    Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-20953MedMay 7, 2025
    risk 0.33cvss 5.1epss 0.00

    Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.

  • CVE-2025-20949MedMay 7, 2025
    risk 0.33cvss 5.1epss 0.00

    Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary file with the privilege of Samsung Members.

  • CVE-2025-20951MedApr 8, 2025
    risk 0.33cvss 5.1epss 0.00

    Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.90.7 allows local attackers to write arbitrary files with the privilege of Galaxy Store.

  • CVE-2025-20902MedFeb 4, 2025
    risk 0.33cvss 5.1epss 0.00

    Improper access control in Media Controller prior to version 1.0.24.5282 allows local attacker to launch activities in MediaController's privilege.

  • CVE-2025-20893MedFeb 4, 2025
    risk 0.33cvss 5.1epss 0.00

    Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications.

  • CVE-2024-49401MedNov 6, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities.

  • CVE-2024-45185MedNov 4, 2024
    risk 0.33cvss 5.1epss 0.00

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, Modem 5300. There is an out-of-bounds write due to a heap overflow in the GPRS…

  • CVE-2024-34648MedSep 4, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

  • CVE-2024-34641MedSep 4, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.

  • CVE-2024-34616MedAug 7, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.

  • CVE-2024-34615MedAug 7, 2024
    risk 0.33cvss 5.1epss 0.00

    Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.

  • CVE-2024-34611MedAug 7, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-34610MedAug 7, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.

  • CVE-2024-27361MedJul 9, 2024
    risk 0.33cvss 5.1epss 0.00

    A vulnerability was discovered in Samsung Mobile Processor Exynos 980, Exynos 990, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, and Exynos 2400 that involves a time-of-check to time-of-use (TOCTOU) race condition, which can lead to a Denial of Service.

  • CVE-2024-20885MedJun 4, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.

  • CVE-2024-20870MedMay 7, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.

  • CVE-2024-20853MedApr 2, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper verification of intent by broadcast receiver vulnerability in ThemeStore prior to 5.3.05.2 allows local attackers to write arbitrary files to sandbox of ThemeStore.

  • CVE-2024-20841MedMar 5, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.

  • CVE-2024-20811MedFeb 6, 2024
    risk 0.33cvss 5.1epss 0.00

    Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.

  • CVE-2023-42574MedDec 5, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerablility in GameHomeCN prior to version 4.2.60.2 allows local attackers to launch arbitrary activity in GameHomeCN.

  • CVE-2023-30735MedOct 4, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant.

  • CVE-2023-30725MedSep 6, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper authentication in LocalProvier of Gallery prior to version 14.5.01.2 allows attacker to access the data in content provider.

  • CVE-2023-30678MedJul 6, 2023
    risk 0.33cvss 5.1epss 0.00

    Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers to write arbitrary file.

  • CVE-2023-30667MedJul 6, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.

  • CVE-2023-21487MedMay 4, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.

  • CVE-2023-21484MedMay 4, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.

  • CVE-2023-21459MedMar 16, 2023
    risk 0.33cvss 5.0epss 0.00

    Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.

  • CVE-2023-21424MedFeb 9, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.

  • CVE-2023-21423MedFeb 9, 2023
    risk 0.33cvss 5.1epss 0.00

    Improper authorization vulnerability in ChnFileShareKit prior to SMR Jan-2023 Release 1 allows attacker to control BLE advertising without permission using unprotected action.

  • CVE-2022-39875MedOct 7, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper component protection vulnerability in Samsung Account prior to version 13.5.0 allows attackers to unauthorized logout.

  • CVE-2022-39855MedOct 7, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in FACM application prior to SMR Oct-2022 Release 1 allows a local attacker to connect arbitrary AP and Bluetooth devices.

  • CVE-2022-36872MedSep 9, 2022
    risk 0.33cvss 5.0epss 0.00

    Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

  • CVE-2022-36871MedSep 9, 2022
    risk 0.33cvss 5.0epss 0.00

    Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

  • CVE-2022-36870MedSep 9, 2022
    risk 0.33cvss 5.0epss 0.00

    Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

  • CVE-2022-36848MedSep 9, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1 allows local attackers to cause local permanent denial of service.

  • CVE-2022-33731MedAug 5, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in DesktopSystemUI prior to SMR Aug-2022 Release 1 allows attackers to enable and disable arbitrary components.

  • CVE-2022-33695MedJul 12, 2022
    risk 0.33cvss 5.1epss 0.00

    Use of improper permission in InputManagerService prior to SMR Jul-2022 Release 1 allows unauthorized access to the service.

  • CVE-2022-30731MedJun 7, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application.

  • CVE-2022-28780MedMay 3, 2022
    risk 0.33cvss 5.0epss 0.00

    Improper access control vulnerability in Weather prior to SMR May-2022 Release 1 allows that attackers can access location information that set in Weather without permission. The patch adds proper protection to prevent access to location information.

  • CVE-2022-28775MedApr 11, 2022
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission.

  • CVE-2021-25503MedNov 5, 2021
    risk 0.33cvss 5.0epss 0.00

    Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.

  • CVE-2021-25489LowKEVOct 6, 2021
    risk 0.33cvss 3.3epss 0.01

    Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.

  • CVE-2021-25453MedSep 9, 2021
    risk 0.33cvss 5.1epss 0.00

    Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth information.

  • CVE-2021-25340MedMar 4, 2021
    risk 0.33cvss 5.1epss 0.00

    Improper access control vulnerability in Samsung keyboard version prior to SMR Feb-2021 Release 1 allows physically proximate attackers to change in arbitrary settings during Initialization State.

  • CVE-2025-53079MedJul 29, 2025
    risk 0.32cvss 4.9epss 0.00

    Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files

  • CVE-2025-20995MedJun 4, 2025
    risk 0.32cvss 4.9epss 0.00

    Improper handling of insufficient permission in ClientProvider in Samsung Internet installed on non-Samsung Device prior to version 28.0.0.59 allows local attackers to read and write arbitrary files.

  • CVE-2024-31955MedOct 15, 2024
    risk 0.32cvss 4.9epss 0.00

    An issue was discovered in Samsung eMMC with KLMAG2GE4A and KLM8G1WEMB firmware. Code bypass through Electromagnetic Fault Injection allows an attacker to successfully authenticate and write to the RPMB (Replay Protected Memory Block) area without possessing secret information.

Page 32 of 47