Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-20871 | Med | 0.32 | 4.9 | 0.00 | May 7, 2024 | Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection. | ||
| CVE-2023-42559 | Med | 0.32 | 4.9 | 0.00 | Dec 5, 2023 | Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time. | ||
| CVE-2022-39847 | Med | 0.32 | 4.9 | 0.00 | Oct 7, 2022 | Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to perform malicious actions. | ||
| CVE-2022-36849 | Med | 0.32 | 4.9 | 0.00 | Sep 9, 2022 | Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions. | ||
| CVE-2022-36847 | Med | 0.32 | 4.9 | 0.00 | Sep 9, 2022 | Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions. | ||
| CVE-2026-21034 | Med | 0.31 | — | 0.00 | Jun 5, 2026 | Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration. | ||
| CVE-2023-43122 | Med | 0.31 | 4.8 | 0.00 | Dec 13, 2023 | Samsung Mobile Processor and Wearable Processor (Exynos 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, and W920) allow Information Disclosure in the Bootloader. | ||
| CVE-2023-42573 | Med | 0.31 | 4.7 | 0.00 | Dec 5, 2023 | PendingIntent hijacking vulnerability in Search Widget prior to version 3.4 in China models allows local attackers to access data. | ||
| CVE-2023-42539 | Med | 0.31 | 4.7 | 0.00 | Nov 7, 2023 | PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data. | ||
| CVE-2023-41911 | Med | 0.31 | 4.7 | 0.00 | Sep 28, 2023 | Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2). | ||
| CVE-2023-42482 | Med | 0.31 | 4.7 | 0.00 | Sep 21, 2023 | Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free. | ||
| CVE-2023-30726 | Med | 0.31 | 4.7 | 0.00 | Sep 6, 2023 | PendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data. | ||
| CVE-2023-30720 | Med | 0.31 | 4.7 | 0.00 | Sep 6, 2023 | PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access. | ||
| CVE-2023-30701 | Med | 0.31 | 4.7 | 0.00 | Aug 10, 2023 | PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access. | ||
| CVE-2023-21490 | Med | 0.31 | 4.7 | 0.00 | May 4, 2023 | Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager. | ||
| CVE-2022-39911 | Med | 0.31 | 4.8 | 0.00 | Dec 8, 2022 | Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass. | ||
| CVE-2022-33727 | Med | 0.31 | 4.8 | 0.00 | Aug 5, 2022 | A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack. | ||
| CVE-2022-33723 | Med | 0.31 | 4.8 | 0.00 | Aug 5, 2022 | A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack. | ||
| CVE-2015-9546 | Med | 0.31 | 4.8 | 0.00 | Apr 10, 2020 | An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences… | ||
| CVE-2016-1919 | Med | 0.31 | 4.7 | 0.00 | Jan 27, 2017 | Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack. | ||
| CVE-2026-21070 | Med | 0.30 | 4.6 | 0.00 | Aug 10, 2026 | Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. | ||
| CVE-2026-21060 | Med | 0.30 | 4.6 | 0.00 | Aug 10, 2026 | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2026-20974 | Med | 0.30 | 4.6 | 0.00 | Jan 9, 2026 | Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock. | ||
| CVE-2025-21063 | Med | 0.30 | 4.6 | 0.00 | Oct 10, 2025 | Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen. | ||
| CVE-2025-21035 | Med | 0.30 | 4.6 | 0.00 | Sep 3, 2025 | Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2023-21467 | Med | 0.30 | 4.6 | 0.00 | Sep 3, 2025 | Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message. | ||
| CVE-2025-20966 | Med | 0.30 | 4.6 | 0.00 | May 7, 2025 | Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2025-20924 | Med | 0.30 | 4.6 | 0.00 | Mar 6, 2025 | Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2025-20898 | Med | 0.30 | 4.6 | 0.00 | Feb 4, 2025 | Improper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2025-20894 | Med | 0.30 | 4.6 | 0.00 | Feb 4, 2025 | Improper access control in Samsung Email prior to version 6.1.97.1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2025-20884 | Med | 0.30 | 4.6 | 0.00 | Feb 4, 2025 | Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2025-20883 | Med | 0.30 | 4.6 | 0.00 | Feb 4, 2025 | Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2024-49407 | Med | 0.30 | 4.6 | 0.00 | Nov 6, 2024 | Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2024-49403 | Med | 0.30 | 4.6 | 0.00 | Nov 6, 2024 | Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access recording files on the lock screen. | ||
| CVE-2024-49402 | Med | 0.30 | 4.6 | 0.00 | Nov 6, 2024 | Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles. | ||
| CVE-2024-34674 | Med | 0.30 | 4.6 | 0.00 | Nov 6, 2024 | Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2024-34653 | Med | 0.30 | 4.6 | 0.00 | Sep 4, 2024 | Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege. | ||
| CVE-2024-34642 | Med | 0.30 | 4.6 | 0.00 | Sep 4, 2024 | Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information. | ||
| CVE-2024-34639 | Med | 0.30 | 4.6 | 0.00 | Sep 4, 2024 | Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation. | ||
| CVE-2024-20882 | Med | 0.30 | 4.6 | 0.00 | Jun 4, 2024 | Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access. | ||
| CVE-2024-20839 | Med | 0.30 | 4.6 | 0.00 | Mar 5, 2024 | Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to access recording files on the lock screen. | ||
| CVE-2024-20827 | Med | 0.30 | 4.6 | 0.00 | Feb 6, 2024 | Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen. | ||
| CVE-2024-20802 | Med | 0.30 | 4.6 | 0.00 | Jan 4, 2024 | Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment. | ||
| CVE-2023-30714 | Med | 0.30 | 4.6 | 0.00 | Sep 6, 2023 | Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock. | ||
| CVE-2023-30708 | Med | 0.30 | 4.6 | 0.01 | Sep 6, 2023 | Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status. | ||
| CVE-2023-30676 | Med | 0.30 | 4.6 | 0.00 | Jul 6, 2023 | Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass. | ||
| CVE-2022-44636 | Med | 0.30 | 4.6 | 0.00 | Dec 13, 2022 | The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E9172511 for 2021 models, xxxA1000, 4x2A0200 for 2022 models. | ||
| CVE-2022-39900 | Med | 0.30 | 4.6 | 0.00 | Dec 8, 2022 | Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch. | ||
| CVE-2022-30730 | Med | 0.30 | 4.6 | 0.00 | Jun 7, 2022 | Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication. | ||
| CVE-2022-28782 | Med | 0.30 | 4.6 | 0.00 | May 3, 2022 | Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package before completion of Setup wizard. The patch blocks entry point of the vulnerability. |
- risk 0.32cvss 4.9epss 0.00
Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.
- risk 0.32cvss 4.9epss 0.00
Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.
- risk 0.32cvss 4.9epss 0.00
Use after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to perform malicious actions.
- risk 0.32cvss 4.9epss 0.00
Use after free vulnerability in sdp_mm_set_process_sensitive function of sdpmm driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.
- risk 0.32cvss 4.9epss 0.00
Use after free vulnerability in mtp_send_signal function of MTP driver prior to SMR Sep-2022 Release 1 allows attackers to perform malicious actions.
- risk 0.31cvss —epss 0.00
Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.
- risk 0.31cvss 4.8epss 0.00
Samsung Mobile Processor and Wearable Processor (Exynos 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, and W920) allow Information Disclosure in the Bootloader.
- risk 0.31cvss 4.7epss 0.00
PendingIntent hijacking vulnerability in Search Widget prior to version 3.4 in China models allows local attackers to access data.
- risk 0.31cvss 4.7epss 0.00
PendingIntent hijacking vulnerability in ChallengeNotificationManager in Samsung Health prior to version 6.25 allows local attackers to access data.
- risk 0.31cvss 4.7epss 0.00
Samsung Mobile Processor Exynos 2200 allows a GPU Double Free (issue 1 of 2).
- risk 0.31cvss 4.7epss 0.00
Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free.
- risk 0.31cvss 4.7epss 0.00
PendingIntent hijacking vulnerability in GameLauncher prior to version 4.2.59.5 allows local attackers to access data.
- risk 0.31cvss 4.7epss 0.00
PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.
- risk 0.31cvss 4.7epss 0.00
PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.
- risk 0.31cvss 4.7epss 0.00
Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.
- risk 0.31cvss 4.8epss 0.00
Improper check or handling of exceptional conditions vulnerability in Samsung Pass prior to version 4.0.06.1 allows attacker to access Samsung Pass.
- risk 0.31cvss 4.8epss 0.00
A vulnerable code in onCreate of SecDevicePickerDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
- risk 0.31cvss 4.8epss 0.00
A vulnerable code in onCreate of BluetoothScanDialog prior to SMR Aug-2022 Release 1, allows attackers to trick the user to select an unwanted bluetooth device via tapjacking/overlay attack.
- risk 0.31cvss 4.8epss 0.00
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream to insert directory traversal sequences…
- risk 0.31cvss 4.7epss 0.00
Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack.
- risk 0.30cvss 4.6epss 0.00
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
- risk 0.30cvss 4.6epss 0.00
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Notes prior to version 4.4.26.71 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper input validation in Samsung Members prior to version 5.2.00.12 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Email prior to version 6.1.97.1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Flow prior to version 4.9.15.7 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Voice Recorder prior to version 21.5.40.37 allows physical attackers to access recording files on the lock screen.
- risk 0.30cvss 4.6epss 0.00
Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.
- risk 0.30cvss 4.6epss 0.00
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
- risk 0.30cvss 4.6epss 0.00
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
- risk 0.30cvss 4.6epss 0.00
Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Voice Recorder prior to versions 21.5.16.01 in Android 12 and Android 13, 21.4.51.02 in Android 14 allows physical attackers to access recording files on the lock screen.
- risk 0.30cvss 4.6epss 0.00
Improper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using physical keyboard on the lockscreen.
- risk 0.30cvss 4.6epss 0.00
Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.
- risk 0.30cvss 4.6epss 0.00
Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.
- risk 0.30cvss 4.6epss 0.01
Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.
- risk 0.30cvss 4.6epss 0.00
Improper access control vulnerability in Samsung Pass prior to version 4.2.03.1 allows physical attackers to access data of Samsung Pass.
- risk 0.30cvss 4.6epss 0.00
The Samsung TV (2021 and 2022 model) smart remote control allows attackers to enable microphone access via Bluetooth spoofing when a user is activating remote control by pressing a button. This is fixed in xxx72510, E9172511 for 2021 models, xxxA1000, 4x2A0200 for 2022 models.
- risk 0.30cvss 4.6epss 0.00
Improper access control vulnerability in Nice Catch prior to SMR Dec-2022 Release 1 allows physical attackers to access contents of all toast generated in the application installed in Secure Folder through Nice Catch.
- risk 0.30cvss 4.6epss 0.00
Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.
- risk 0.30cvss 4.6epss 0.00
Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package before completion of Setup wizard. The patch blocks entry point of the vulnerability.
Page 33 of 47