VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2021-25430MedJul 8, 2021
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.

  • CVE-2021-25429MedJul 8, 2021
    risk 0.28cvss 4.3epss 0.00

    Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth application.

  • CVE-2021-25378MedApr 9, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.

  • CVE-2017-18667MedApr 7, 2020
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. Attackers can prevent users from learning that SMS storage space has been exhausted. The Samsung ID is SVE-2017-8702 (June 2017).

  • CVE-2017-18653MedApr 7, 2020
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.x) software. The Email application allows attackers to send emails on behalf of any user via a broadcasted intent. The Samsung ID is SVE-2017-9357 (September 2017).

  • CVE-2016-11050MedApr 7, 2020
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attacker can rewrite the IMEI by flashing crafted firmware. The Samsung ID is SVE-2016-5562 (March 2016).

  • CVE-2019-6744MedFeb 10, 2020
    risk 0.28cvss 4.3epss 0.00

    This vulnerability allows local attackers to disclose sensitive information on affected installations of Samsung Knox 1.2.02.39 on Samsung Galaxy S9 build G9600ZHS3ARL1 Secure Folder. An attacker must first obtain physical access to the device in order to exploit this…

  • CVE-2018-16268MedJan 22, 2020
    risk 0.28cvss 4.3epss 0.01

    The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations. Such actions include playing an arbitrary sound file or DTMF tones. This affects Tizen before 5.0 M1,…

  • CVE-2013-4764MedDec 27, 2019
    risk 0.28cvss 4.3epss 0.00

    Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.

  • CVE-2018-14853MedDec 17, 2018
    risk 0.28cvss 4.3epss 0.01

    A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device to…

  • CVE-2026-33957MedSep 14, 2026
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in CustOS Driver in Samsung Mobile Processor Exynos 1580. Requesting oversized shared memory from the custos_iwc device enables out-of-bounds read and write, potentially leading to memory corruption or information leakage.

  • CVE-2026-23791MedSep 14, 2026
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory…

  • CVE-2026-23790MedSep 14, 2026
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory…

  • CVE-2026-23788MedSep 14, 2026
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.

  • CVE-2026-23787MedSep 14, 2026
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-Free in the Exynos DRM HDR driver (due to improper cleanup upon vmap failure) leads to a kernel crash.

  • CVE-2026-40448MedApr 22, 2026
    risk 0.27cvss 5.3epss 0.00

    Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung Open Source ONE. Affected version is prior to commit  1.30.0.

  • CVE-2025-58476MedDec 2, 2025
    risk 0.27cvss 4.2epss 0.00

    Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.

  • CVE-2025-21037MedSep 3, 2025
    risk 0.27cvss 4.1epss 0.00

    Improper access control in Samsung Notes prior to version 4.4.30.63 allows physical attackers to access data across multiple user profiles. User interaction is required for triggering this vulnerability.

  • CVE-2025-20999MedJul 8, 2025
    risk 0.27cvss 4.1epss 0.00

    Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.

  • CVE-2025-20886MedFeb 4, 2025
    risk 0.27cvss 4.1epss 0.00

    Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.

  • CVE-2024-34673MedNov 6, 2024
    risk 0.27cvss 4.1epss 0.00

    Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.

  • CVE-2024-34664MedOct 8, 2024
    risk 0.27cvss 4.1epss 0.00

    Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment.

  • CVE-2024-20873MedJun 4, 2024
    risk 0.27cvss 4.2epss 0.00

    Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2024-20842MedApr 2, 2024
    risk 0.27cvss 4.2epss 0.00

    Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2024-20833MedMar 5, 2024
    risk 0.27cvss 4.1epss 0.00

    Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.

  • CVE-2023-21462MedMar 16, 2023
    risk 0.27cvss 4.2epss 0.00

    The sensitive information exposure vulnerability in Quick Share Agent prior to versions 3.5.14.18 in Android 12 and 3.5.16.20 in Android 13 allows to local attacker to access MAC address without related permission.

  • CVE-2023-21457MedMar 16, 2023
    risk 0.27cvss 4.1epss 0.00

    Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.

  • CVE-2023-21432MedFeb 9, 2023
    risk 0.27cvss 4.2epss 0.00

    Improper access control vulnerabilities in Smart Things prior to 1.7.93 allows to attacker to invite others without authorization of the owner.

  • CVE-2022-30740MedJun 7, 2022
    risk 0.27cvss 4.1epss 0.00

    Improper auto-fill algorithm in Samsung Internet prior to version 17.0.1.69 allows physical attackers to guess stored credit card numbers.

  • CVE-2022-25820MedMar 10, 2022
    risk 0.27cvss 4.2epss 0.00

    A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.

  • CVE-2022-25816MedMar 10, 2022
    risk 0.27cvss 4.1epss 0.00

    Improper authentication in Samsung Lock and mask apps setting prior to SMR Mar-2022 Release 1 allows attacker to change enable/disable without authentication

  • CVE-2022-24932MedMar 10, 2022
    risk 0.27cvss 4.2epss 0.00

    Improper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker package installation before finishing Setup wizard.

  • CVE-2022-24929MedMar 10, 2022
    risk 0.27cvss 4.1epss 0.00

    Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.

  • CVE-2022-24927MedFeb 11, 2022
    risk 0.27cvss 4.2epss 0.00

    Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.

  • CVE-2021-25476MedOct 6, 2021
    risk 0.27cvss 4.1epss 0.00

    An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.

  • CVE-2019-12762MedJun 6, 2019
    risk 0.27cvss 4.2epss 0.00

    Xiaomi Mi 5s Plus devices allow attackers to trigger touchscreen anomalies via a radio signal between 198 kHz and 203 kHz, as demonstrated by a transmitter and antenna hidden just beneath the surface of a coffee-shop table, aka Ghost Touch.

  • CVE-2018-12038MedNov 20, 2018
    risk 0.27cvss 4.2epss 0.01

    An issue was discovered on Samsung 840 EVO devices. Vendor-specific commands may allow access to the disk-encryption key.

  • CVE-2015-7268MedNov 27, 2017
    risk 0.27cvss 4.2epss 0.00

    Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or ThinkPad W541 laptops with BIOS 2.21, or in Opal or eDrive mode on Dell…

  • CVE-2015-7267MedNov 27, 2017
    risk 0.27cvss 4.2epss 0.00

    Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with…

  • CVE-2026-23792MedSep 14, 2026
    risk 0.26cvss 4.0epss 0.00

    An issue was discovered in NR RRC in Samsung Mobile Processor and Modem Exynos 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W1000, Modem 5300, Modem 5400, and Modem 5410. Incorrect handling of unauthenticated downlink RRC Setup messages can cause the baseband to…

  • CVE-2026-40447MedApr 13, 2026
    risk 0.26cvss 5.1epss 0.00

    Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavior.This issue affects Escargot: 97e8115ab1110bc502b4b5e4a0c689a71520d335.

  • CVE-2025-58487MedDec 2, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper authorization in Samsung Account prior to version 15.5.01.1 allows local attacker to launch arbitrary activity with Samsung Account privilege.

  • CVE-2025-58486MedDec 2, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper input validation in Samsung Account prior to version 15.5.01.1 allows local attacker to execute arbitrary script.

  • CVE-2025-58484MedDec 2, 2025
    risk 0.26cvss 4.0epss 0.00

    Incorrect default permissions in Samsung Cloud Assistant prior to version 8.0.03.8 allows local attacker to access partial data in sandbox.

  • CVE-2025-21070MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

  • CVE-2025-21069MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

  • CVE-2025-21068MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

  • CVE-2025-21067MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

  • CVE-2025-21066MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

  • CVE-2025-21057MedOct 10, 2025
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in Samsung Notes prior to version 4.4.30.63 allows local attackers to access shared notes.

Page 37 of 47