Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27832 | Med | 0.26 | 4.0 | 0.00 | Apr 11, 2022 | Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file. | ||
| CVE-2022-27825 | Med | 0.26 | 4.0 | 0.00 | Apr 11, 2022 | Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file. | ||
| CVE-2022-27824 | Med | 0.26 | 4.0 | 0.00 | Apr 11, 2022 | Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file | ||
| CVE-2022-27823 | Med | 0.26 | 4.0 | 0.00 | Apr 11, 2022 | Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file. | ||
| CVE-2022-27821 | Med | 0.26 | 4.0 | 0.00 | Apr 11, 2022 | Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via crafted image file. | ||
| CVE-2022-25832 | Med | 0.26 | 4.0 | 0.00 | Apr 11, 2022 | Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication. | ||
| CVE-2022-25824 | Med | 0.26 | 4.0 | 0.00 | Mar 10, 2022 | Improper access control vulnerability in BixbyTouch prior to version 2.2.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview. | ||
| CVE-2022-25822 | Med | 0.26 | 4.0 | 0.00 | Mar 10, 2022 | An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash. | ||
| CVE-2022-25817 | Med | 0.26 | 4.0 | 0.00 | Mar 10, 2022 | Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent. | ||
| CVE-2022-24923 | Med | 0.26 | 4.0 | 0.00 | Feb 11, 2022 | Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview. | ||
| CVE-2022-24003 | Med | 0.26 | 4.0 | 0.01 | Feb 11, 2022 | Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision via unprotected intent. | ||
| CVE-2022-24002 | Med | 0.26 | 4.0 | 0.01 | Feb 11, 2022 | Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity. | ||
| CVE-2022-23997 | Med | 0.26 | 4.0 | 0.00 | Feb 11, 2022 | Unprotected component vulnerability in StTheaterModeDurationAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to disable theater mode without a proper permission. | ||
| CVE-2022-23996 | Med | 0.26 | 4.0 | 0.00 | Feb 11, 2022 | Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission. | ||
| CVE-2022-23995 | Med | 0.26 | 4.0 | 0.00 | Feb 11, 2022 | Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission. | ||
| CVE-2022-22272 | Med | 0.26 | 4.0 | 0.00 | Jan 10, 2022 | Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission | ||
| CVE-2022-22269 | Med | 0.26 | 4.0 | 0.00 | Jan 10, 2022 | Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address. | ||
| CVE-2022-22267 | Med | 0.26 | 4.0 | 0.00 | Jan 10, 2022 | Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information. | ||
| CVE-2022-22266 | Med | 0.26 | 4.0 | 0.00 | Jan 10, 2022 | (Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission. | ||
| CVE-2022-22263 | Med | 0.26 | 4.0 | 0.00 | Jan 10, 2022 | Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity. | ||
| CVE-2021-25526 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2021 | Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action. | ||
| CVE-2021-25524 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2021 | Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID. | ||
| CVE-2021-25523 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2021 | Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID. | ||
| CVE-2021-25521 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2021 | Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet. | ||
| CVE-2021-25519 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2021 | An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission. | ||
| CVE-2021-25515 | Med | 0.26 | 4.0 | 0.00 | Dec 8, 2021 | An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID. | ||
| CVE-2021-25506 | Med | 0.26 | 4.0 | 0.00 | Nov 5, 2021 | Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service. | ||
| CVE-2021-25504 | Med | 0.26 | 4.0 | 0.00 | Nov 5, 2021 | Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information. | ||
| CVE-2021-25494 | Med | 0.26 | 4.0 | 0.00 | Oct 6, 2021 | A possible buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution. | ||
| CVE-2021-25493 | Med | 0.26 | 4.0 | 0.00 | Oct 6, 2021 | Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read | ||
| CVE-2021-25484 | Med | 0.26 | 4.0 | 0.00 | Oct 6, 2021 | Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event. | ||
| CVE-2021-25483 | Med | 0.26 | 4.0 | 0.00 | Oct 6, 2021 | Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read. | ||
| CVE-2021-25472 | Med | 0.26 | 4.0 | 0.00 | Oct 6, 2021 | An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information. | ||
| CVE-2021-25463 | Med | 0.26 | 4.0 | 0.00 | Sep 9, 2021 | Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview. | ||
| CVE-2021-25461 | Med | 0.26 | 4.0 | 0.00 | Sep 9, 2021 | An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow. | ||
| CVE-2021-25460 | Med | 0.26 | 4.0 | 0.00 | Sep 9, 2021 | An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService. | ||
| CVE-2021-25459 | Med | 0.26 | 4.0 | 0.00 | Sep 9, 2021 | An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService. | ||
| CVE-2021-25392 | Med | 0.26 | 4.0 | 0.00 | Jun 11, 2021 | Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path. | ||
| CVE-2021-25391 | Med | 0.26 | 4.0 | 0.00 | Jun 11, 2021 | Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action. | ||
| CVE-2021-25390 | Med | 0.26 | 4.0 | 0.00 | Jun 11, 2021 | Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action. | ||
| CVE-2021-25379 | Med | 0.26 | 4.0 | 0.00 | Apr 9, 2021 | Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action. | ||
| CVE-2021-25364 | Med | 0.26 | 4.0 | 0.00 | Apr 9, 2021 | A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information. | ||
| CVE-2021-25359 | Med | 0.26 | 4.0 | 0.00 | Apr 9, 2021 | An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications. | ||
| CVE-2021-25358 | Med | 0.26 | 4.0 | 0.00 | Apr 9, 2021 | A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications. | ||
| CVE-2021-25345 | Med | 0.26 | 4.0 | 0.00 | Mar 4, 2021 | Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel panic due to unsupported format. | ||
| CVE-2021-25343 | Med | 0.26 | 4.0 | 0.00 | Mar 4, 2021 | Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider. | ||
| CVE-2021-25342 | Med | 0.26 | 4.0 | 0.00 | Mar 4, 2021 | Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider. | ||
| CVE-2021-25341 | Med | 0.26 | 4.0 | 0.00 | Mar 4, 2021 | Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider. | ||
| CVE-2018-12037 | Med | 0.26 | 4.0 | 0.00 | Nov 20, 2018 | An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk… | ||
| CVE-2023-30704 | Low | 0.25 | 3.8 | 0.00 | Aug 10, 2023 | Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication. |
- risk 0.26cvss 4.0epss 0.00
Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.
- risk 0.26cvss 4.0epss 0.00
Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.
- risk 0.26cvss 4.0epss 0.00
Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file
- risk 0.26cvss 4.0epss 0.00
Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.
- risk 0.26cvss 4.0epss 0.00
Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via crafted image file.
- risk 0.26cvss 4.0epss 0.00
Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in BixbyTouch prior to version 2.2.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.
- risk 0.26cvss 4.0epss 0.00
An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.
- risk 0.26cvss 4.0epss 0.00
Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.
- risk 0.26cvss 4.0epss 0.01
Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision via unprotected intent.
- risk 0.26cvss 4.0epss 0.01
Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.
- risk 0.26cvss 4.0epss 0.00
Unprotected component vulnerability in StTheaterModeDurationAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to disable theater mode without a proper permission.
- risk 0.26cvss 4.0epss 0.00
Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.
- risk 0.26cvss 4.0epss 0.00
Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.
- risk 0.26cvss 4.0epss 0.00
Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission
- risk 0.26cvss 4.0epss 0.00
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
- risk 0.26cvss 4.0epss 0.00
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
- risk 0.26cvss 4.0epss 0.00
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
- risk 0.26cvss 4.0epss 0.00
Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.
- risk 0.26cvss 4.0epss 0.00
Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.
- risk 0.26cvss 4.0epss 0.00
Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.
- risk 0.26cvss 4.0epss 0.00
Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.
- risk 0.26cvss 4.0epss 0.00
Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.
- risk 0.26cvss 4.0epss 0.00
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.
- risk 0.26cvss 4.0epss 0.00
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.
- risk 0.26cvss 4.0epss 0.00
Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.
- risk 0.26cvss 4.0epss 0.00
Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.
- risk 0.26cvss 4.0epss 0.00
A possible buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.
- risk 0.26cvss 4.0epss 0.00
Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read
- risk 0.26cvss 4.0epss 0.00
Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.
- risk 0.26cvss 4.0epss 0.00
Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.
- risk 0.26cvss 4.0epss 0.00
An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.
- risk 0.26cvss 4.0epss 0.00
An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.
- risk 0.26cvss 4.0epss 0.00
An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.
- risk 0.26cvss 4.0epss 0.00
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.
- risk 0.26cvss 4.0epss 0.00
Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.
- risk 0.26cvss 4.0epss 0.00
Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
- risk 0.26cvss 4.0epss 0.00
Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
- risk 0.26cvss 4.0epss 0.00
Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.
- risk 0.26cvss 4.0epss 0.00
A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.
- risk 0.26cvss 4.0epss 0.00
An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.
- risk 0.26cvss 4.0epss 0.00
A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.
- risk 0.26cvss 4.0epss 0.00
Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel panic due to unsupported format.
- risk 0.26cvss 4.0epss 0.00
Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider.
- risk 0.26cvss 4.0epss 0.00
Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.
- risk 0.26cvss 4.0epss 0.00
Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider.
- risk 0.26cvss 4.0epss 0.00
An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk…
- risk 0.25cvss 3.8epss 0.00
Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.
Page 41 of 47