VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2021-25480MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.00

    A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote denial of service on mobile network connection.

  • CVE-2021-25477MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.01

    An improper error handling in Mediatek RRC Protocol stack prior to SMR Oct-2021 Release 1 allows modem crash and remote denial of service.

  • CVE-2021-25474MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.00

    Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.

  • CVE-2021-25473MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.00

    Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadia_full value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory reset.

  • CVE-2021-25468MedOct 6, 2021
    risk 0.29cvss 4.4epss 0.00

    A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to read arbitrary memory address.

  • CVE-2021-25450MedSep 9, 2021
    risk 0.29cvss 4.5epss 0.00

    Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.

  • CVE-2021-25411MedJun 11, 2021
    risk 0.29cvss 4.4epss 0.00

    Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.

  • CVE-2021-25339MedMar 4, 2021
    risk 0.29cvss 4.4epss 0.00

    Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to corrupt EL2 memory.

  • CVE-2021-25338MedMar 4, 2021
    risk 0.29cvss 4.4epss 0.00

    Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given a compromised kernel, to write certain part of RKP EL2 memory region.

  • CVE-2026-20985MedFeb 4, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-58480MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-58479MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-58478MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-58477MedDec 2, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-21075MedNov 5, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-21074MedNov 5, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2025-48025MedOct 20, 2025
    risk 0.28cvss 4.3epss 0.00

    In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000, there is an improper access control vulnerability related to a log file.

  • CVE-2025-21055MedOct 10, 2025
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

  • CVE-2022-39888MedSep 4, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in retrieveExternalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to access to Proxy information.

  • CVE-2025-21030MedSep 3, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background.

  • CVE-2025-21014MedAug 6, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-20956MedMay 7, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings.

  • CVE-2024-48883MedJan 13, 2025
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, and Modem 5300. The UE incorrectly handles a malformed uplink scheduling…

  • CVE-2024-49421MedDec 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.

  • CVE-2024-49419MedDec 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Insufficient verification of url authenticity in GamingHub prior to version 6.1.03.4 in Korea, 7.1.02.4 in Global allows remote attackers to load an arbitrary URL in its webview.

  • CVE-2024-49411MedDec 3, 2024
    risk 0.28cvss 4.3epss 0.00

    Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.

  • CVE-2024-34661MedSep 4, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper handling of insufficient permissions in Samsung Assistant prior to version 9.1.00.7 allows remote attackers to access location data. User interaction is required for triggering this vulnerability.

  • CVE-2024-20894MedJul 2, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.

  • CVE-2024-32672MedMay 14, 2024
    risk 0.28cvss 5.3epss 0.01

    A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via crafted input. This issue affects Escargot: 4.0.0.

  • CVE-2024-32669MedMay 14, 2024
    risk 0.28cvss 5.3epss 0.01

    Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test code and does not include in the release. This issue affects escargot: 4.0.0.

  • CVE-2024-20856MedMay 7, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.

  • CVE-2023-40292MedAug 14, 2023
    risk 0.28cvss 4.3epss 0.01

    Harman Infotainment 20190525031613 and later discloses the IP address via CarPlay CTRL packets.

  • CVE-2023-30685MedAug 10, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.

  • CVE-2023-30684MedAug 10, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.

  • CVE-2023-30683MedAug 10, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.

  • CVE-2023-30682MedAug 10, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.

  • CVE-2023-36482MedAug 8, 2023
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in Samsung NFC S3NRN4V, S3NSN4V, S3NSEN4, SEN82AB, and S3NRN82. A buffer copy without checking its input size can cause an NFC service restart.

  • CVE-2023-30641MedJul 6, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.

  • CVE-2023-30640MedJul 6, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.

  • CVE-2023-21426MedFeb 9, 2023
    risk 0.28cvss 4.3epss 0.00

    Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.

  • CVE-2023-21425MedFeb 9, 2023
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.

  • CVE-2023-21419MedFeb 9, 2023
    risk 0.28cvss 4.3epss 0.00

    An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.

  • CVE-2022-39891MedNov 9, 2022
    risk 0.28cvss 4.3epss 0.00

    Heap overflow vulnerability in parse_pce function in libsavsaudio.so in Editor Lite prior to version 4.0.41.3 allows attacker to get information.

  • CVE-2022-39887MedNov 9, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.

  • CVE-2022-39884MedNov 9, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.

  • CVE-2022-39873MedOct 7, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows physical attackers to add bookmarks in secret mode without user authentication.

  • CVE-2022-30738MedJun 7, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.

  • CVE-2022-28777MedApr 11, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute call function without CALL_PHONE permission.

  • CVE-2022-27841MedApr 11, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

  • CVE-2022-23433MedFeb 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in Andoid Q(10) allows attackers to register reminders or execute exporeted activities remotely.

Page 36 of 47