VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2024-20871MedMay 7, 2024
    risk 0.32cvss 4.9epss 0.00

    Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.

  • CVE-2023-42559MedDec 5, 2023
    risk 0.32cvss 4.9epss 0.00

    Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.

  • CVE-2022-39847MedOct 7, 2022
    risk 0.32cvss 4.9epss 0.00

    Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to perform malicious actions.

  • CVE-2022-36849MedSep 9, 2022
    risk 0.32cvss 4.9epss 0.00

    Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.

  • CVE-2022-36847MedSep 9, 2022
    risk 0.32cvss 4.9epss 0.00

    Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.

  • CVE-2026-21034MedJun 5, 2026
    risk 0.31cvss —epss 0.00

    Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.

  • CVE-2023-43122MedDec 13, 2023
    risk 0.31cvss 4.8epss 0.00

    Samsung Mobile Processor and Wearable Processor (Exynos 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, and W920) allow Information Disclosure in the Bootloader.

  • CVE-2023-42573MedDec 5, 2023
    risk 0.31cvss 4.7epss 0.00

    PendingIntent hijacking vulnerability in Search Widget prior to version 3.4 in China models allows local attackers to access data.

  • CVE-2023-42539MedNov 7, 2023
    risk 0.31cvss 4.7epss 0.00

    PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.

  • CVE-2023-41911MedSep 28, 2023
    risk 0.31cvss 4.7epss 0.00

    Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2).

  • CVE-2023-42482MedSep 21, 2023
    risk 0.31cvss 4.7epss 0.00

    Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free.

  • CVE-2023-30726MedSep 6, 2023
    risk 0.31cvss 4.7epss 0.00

    PendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data.

  • CVE-2023-30720MedSep 6, 2023
    risk 0.31cvss 4.7epss 0.00

    PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.

  • CVE-2023-30701MedAug 10, 2023
    risk 0.31cvss 4.7epss 0.00

    PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.

  • CVE-2023-21490MedMay 4, 2023
    risk 0.31cvss 4.7epss 0.00

    Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.

  • CVE-2022-39911MedDec 8, 2022
    risk 0.31cvss 4.8epss 0.00

    Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass.

  • CVE-2022-33727MedAug 5, 2022
    risk 0.31cvss 4.8epss 0.00

    A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

  • CVE-2022-33723MedAug 5, 2022
    risk 0.31cvss 4.8epss 0.00

    A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.

  • CVE-2015-9546MedApr 10, 2020
    risk 0.31cvss 4.8epss 0.00

    An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences…

  • CVE-2016-1919MedJan 27, 2017
    risk 0.31cvss 4.7epss 0.00

    Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack.

  • CVE-2026-21070MedAug 10, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.

  • CVE-2026-21060MedAug 10, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.

  • CVE-2026-20974MedJan 9, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.

  • CVE-2025-21063MedOct 10, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen.

  • CVE-2025-21035MedSep 3, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles.

  • CVE-2023-21467MedSep 3, 2025
    risk 0.30cvss 4.6epss 0.00

    Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.

  • CVE-2025-20966MedMay 7, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.

  • CVE-2025-20924MedMar 6, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across multiple user profiles.

  • CVE-2025-20898MedFeb 4, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across multiple user profiles.

  • CVE-2025-20894MedFeb 4, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Samsung Email prior to version 6.1.97.1 allows physical attackers to access data across multiple user profiles.

  • CVE-2025-20884MedFeb 4, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.

  • CVE-2025-20883MedFeb 4, 2025
    risk 0.30cvss 4.6epss 0.00

    Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.

  • CVE-2024-49407MedNov 6, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.

  • CVE-2024-49403MedNov 6, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access recording files on the lock screen.

  • CVE-2024-49402MedNov 6, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.

  • CVE-2024-34674MedNov 6, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.

  • CVE-2024-34653MedSep 4, 2024
    risk 0.30cvss 4.6epss 0.00

    Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

  • CVE-2024-34642MedSep 4, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

  • CVE-2024-34639MedSep 4, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.

  • CVE-2024-20882MedJun 4, 2024
    risk 0.30cvss 4.6epss 0.00

    Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.

  • CVE-2024-20839MedMar 5, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to access recording files on the lock screen.

  • CVE-2024-20827MedFeb 6, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.

  • CVE-2024-20802MedJan 4, 2024
    risk 0.30cvss 4.6epss 0.00

    Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.

  • CVE-2023-30714MedSep 6, 2023
    risk 0.30cvss 4.6epss 0.00

    Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.

  • CVE-2023-30708MedSep 6, 2023
    risk 0.30cvss 4.6epss 0.01

    Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.

  • CVE-2023-30676MedJul 6, 2023
    risk 0.30cvss 4.6epss 0.00

    Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass.

  • CVE-2022-44636MedDec 13, 2022
    risk 0.30cvss 4.6epss 0.00

    The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E9172511 for 2021 models, xxxA1000, 4x2A0200 for 2022 models.

  • CVE-2022-39900MedDec 8, 2022
    risk 0.30cvss 4.6epss 0.00

    Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch.

  • CVE-2022-30730MedJun 7, 2022
    risk 0.30cvss 4.6epss 0.00

    Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.

  • CVE-2022-28782MedMay 3, 2022
    risk 0.30cvss 4.6epss 0.00

    Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package before completion of Setup wizard. The patch blocks entry point of the vulnerability.

Page 33 of 47