VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2022-27832MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper boundary check in media.extractor library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via a crafted media file.

  • CVE-2022-27825MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

  • CVE-2022-27824MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file

  • CVE-2022-27823MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.

  • CVE-2022-27821MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows attackers to cause denial of service via crafted image file.

  • CVE-2022-25832MedApr 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authentication vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to use locked Myfiles app without authentication.

  • CVE-2022-25824MedMar 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in BixbyTouch prior to version 2.2.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

  • CVE-2022-25822MedMar 10, 2022
    risk 0.26cvss 4.0epss 0.00

    An use after free vulnerability in sdp driver prior to SMR Mar-2022 Release 1 allows kernel crash.

  • CVE-2022-25817MedMar 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.

  • CVE-2022-24923MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China models allows untrusted applications to load arbitrary URL and local files in webview.

  • CVE-2022-24003MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.01

    Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision via unprotected intent.

  • CVE-2022-24002MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.01

    Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.

  • CVE-2022-23997MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected component vulnerability in StTheaterModeDurationAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to disable theater mode without a proper permission.

  • CVE-2022-23996MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected component vulnerability in StTheaterModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to enable bedtime mode without a proper permission.

  • CVE-2022-23995MedFeb 11, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected component vulnerability in StBedtimeModeAlarmReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

  • CVE-2022-22272MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission

  • CVE-2022-22269MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.

  • CVE-2022-22267MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.

  • CVE-2022-22266MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    (Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.

  • CVE-2022-22263MedJan 10, 2022
    risk 0.26cvss 4.0epss 0.00

    Unprotected dynamic receiver in SecSettings prior to SMR Jan-2022 Release 1 allows untrusted applications to launch arbitrary activity.

  • CVE-2021-25526MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.

  • CVE-2021-25524MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    Insecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.

  • CVE-2021-25523MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    Insecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.

  • CVE-2021-25521MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    Insecure caller check in sharevia deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applications to get current tab URL in Samsung Internet.

  • CVE-2021-25519MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.

  • CVE-2021-25515MedDec 8, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.

  • CVE-2021-25506MedNov 5, 2021
    risk 0.26cvss 4.0epss 0.00

    Non-existent provider in Samsung Health prior to 6.19.1.0001 allows attacker to access it via malicious content provider or lead to denial of service.

  • CVE-2021-25504MedNov 5, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.

  • CVE-2021-25494MedOct 6, 2021
    risk 0.26cvss 4.0epss 0.00

    A possible buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.

  • CVE-2021-25493MedOct 6, 2021
    risk 0.26cvss 4.0epss 0.00

    Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read

  • CVE-2021-25484MedOct 6, 2021
    risk 0.26cvss 4.0epss 0.00

    Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.

  • CVE-2021-25483MedOct 6, 2021
    risk 0.26cvss 4.0epss 0.00

    Lack of boundary checking of a buffer in livfivextractor library prior to SMR Oct-2021 Release 1 allows OOB read.

  • CVE-2021-25472MedOct 6, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth information.

  • CVE-2021-25463MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.

  • CVE-2021-25461MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.

  • CVE-2021-25460MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate BlockchainTZService.

  • CVE-2021-25459MedSep 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start BlockchainTZService.

  • CVE-2021-25392MedJun 11, 2021
    risk 0.26cvss 4.0epss 0.00

    Improper protection of backup path configuration in Samsung Dex prior to SMR MAY-2021 Release 1 allows local attackers to get sensitive information via changing the path.

  • CVE-2021-25391MedJun 11, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

  • CVE-2021-25390MedJun 11, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

  • CVE-2021-25379MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.

  • CVE-2021-25364MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    A pendingIntent hijacking vulnerability in Secure Folder prior to SMR APR-2021 Release 1 allows unprivileged applications to access contact information.

  • CVE-2021-25359MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.

  • CVE-2021-25358MedApr 9, 2021
    risk 0.26cvss 4.0epss 0.00

    A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.

  • CVE-2021-25345MedMar 4, 2021
    risk 0.26cvss 4.0epss 0.00

    Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel panic due to unsupported format.

  • CVE-2021-25343MedMar 4, 2021
    risk 0.26cvss 4.0epss 0.00

    Calling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0) and above) allows unauthorized actions including denial of service attack by hijacking the provider.

  • CVE-2021-25342MedMar 4, 2021
    risk 0.26cvss 4.0epss 0.00

    Calling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijacking the provider.

  • CVE-2021-25341MedMar 4, 2021
    risk 0.26cvss 4.0epss 0.00

    Calling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack by hijacking the provider.

  • CVE-2018-12037MedNov 20, 2018
    risk 0.26cvss 4.0epss 0.00

    An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk…

  • CVE-2023-30704LowAug 10, 2023
    risk 0.25cvss 3.8epss 0.00

    Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.

Page 41 of 47