Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1230 | Low | 0.25 | 3.9 | 0.00 | Mar 28, 2023 | This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phones. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The… | ||
| CVE-2022-39910 | Low | 0.25 | 3.9 | 0.00 | Dec 8, 2022 | Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view. | ||
| CVE-2022-36851 | Low | 0.25 | 3.9 | 0.00 | Sep 9, 2022 | Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device. | ||
| CVE-2022-24001 | Low | 0.25 | 3.8 | 0.00 | Feb 11, 2022 | Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel. | ||
| CVE-2022-24000 | Low | 0.25 | 3.9 | 0.00 | Feb 11, 2022 | PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent. | ||
| CVE-2022-23999 | Low | 0.25 | 3.9 | 0.00 | Feb 11, 2022 | PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent. | ||
| CVE-2022-23427 | Low | 0.25 | 3.9 | 0.00 | Feb 11, 2022 | PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent. | ||
| CVE-2022-22287 | Low | 0.25 | 3.9 | 0.00 | Jan 10, 2022 | Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox. | ||
| CVE-2021-25527 | Low | 0.25 | 3.8 | 0.00 | Dec 8, 2021 | Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication. | ||
| CVE-2021-25475 | Low | 0.25 | 3.9 | 0.00 | Oct 6, 2021 | A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution. | ||
| CVE-2023-50804 | Low | 0.24 | 3.7 | 0.00 | Jun 5, 2024 | An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not… | ||
| CVE-2023-50803 | Low | 0.24 | 3.7 | 0.00 | Jun 5, 2024 | An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not… | ||
| CVE-2021-25471 | Low | 0.24 | 3.7 | 0.00 | Oct 6, 2021 | A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion. | ||
| CVE-2021-25367 | Low | 0.24 | 3.7 | 0.01 | Mar 25, 2021 | Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission. | ||
| CVE-2026-33970 | Low | 0.23 | 3.5 | 0.00 | Sep 14, 2026 | An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when… | ||
| CVE-2023-41270 | Low | 0.23 | 3.5 | 0.00 | Nov 8, 2023 | Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-1033.2 and before allows attackers to cause a denial of service via WPS attack tools. | ||
| CVE-2022-39892 | Low | 0.23 | 3.6 | 0.00 | Nov 9, 2022 | Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature. | ||
| CVE-2022-39863 | Low | 0.23 | 3.6 | 0.00 | Oct 7, 2022 | Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permission. | ||
| CVE-2020-13838 | Low | 0.23 | 3.5 | 0.00 | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not block access to Quick Panel and notifications. The Samsung ID is SVE-2020-17187 (June 2020). | ||
| CVE-2020-13837 | Low | 0.23 | 3.5 | 0.00 | Jun 4, 2020 | An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does not block Quick Panel access to Music Share. The Samsung ID is SVE-2020-17145 (June 2020). | ||
| CVE-2026-91826 | Med | 0.22 | 4.4 | 0.00 | Sep 15, 2026 | Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39. | ||
| CVE-2026-49509 | Med | 0.22 | 4.4 | 0.00 | Sep 4, 2026 | Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630. | ||
| CVE-2026-21062 | Low | 0.21 | 3.3 | 0.00 | Aug 10, 2026 | Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data. | ||
| CVE-2026-21027 | Low | 0.21 | 3.3 | 0.00 | Jun 5, 2026 | Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function. | ||
| CVE-2026-21012 | Low | 0.21 | 3.3 | 0.00 | Apr 13, 2026 | External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege. | ||
| CVE-2026-20992 | Low | 0.21 | 3.3 | 0.00 | Mar 16, 2026 | Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application. | ||
| CVE-2026-20972 | Low | 0.21 | 3.3 | 0.00 | Jan 9, 2026 | Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB. | ||
| CVE-2025-21077 | Low | 0.21 | 3.3 | 0.00 | Nov 5, 2025 | Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity with Samsung Email privilege. | ||
| CVE-2025-21024 | Low | 0.21 | 3.3 | 0.00 | Aug 6, 2025 | Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information. | ||
| CVE-2025-21023 | Low | 0.21 | 3.3 | 0.00 | Aug 6, 2025 | Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information. | ||
| CVE-2025-21022 | Low | 0.21 | 3.3 | 0.00 | Aug 6, 2025 | Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information. | ||
| CVE-2025-20977 | Low | 0.21 | 3.3 | 0.00 | May 7, 2025 | Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20895 | Low | 0.21 | 3.2 | 0.00 | Feb 4, 2025 | Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard. | ||
| CVE-2024-34671 | Low | 0.21 | 3.3 | 0.00 | Oct 8, 2024 | Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-34640 | Low | 0.21 | 3.3 | 0.00 | Sep 4, 2024 | Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration. | ||
| CVE-2024-34602 | Low | 0.21 | 3.3 | 0.00 | Jul 8, 2024 | Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-20836 | Low | 0.21 | 3.3 | 0.00 | Mar 5, 2024 | Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory. | ||
| CVE-2024-20834 | Low | 0.21 | 3.3 | 0.00 | Mar 5, 2024 | The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission. | ||
| CVE-2024-20810 | Low | 0.21 | 3.3 | 0.00 | Feb 6, 2024 | Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20807 | Low | 0.21 | 3.3 | 0.00 | Jan 4, 2024 | Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information. | ||
| CVE-2024-20805 | Low | 0.21 | 3.3 | 0.00 | Jan 4, 2024 | Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file. | ||
| CVE-2023-42572 | Low | 0.21 | 3.3 | 0.00 | Dec 5, 2023 | Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information. | ||
| CVE-2023-42556 | Low | 0.21 | 3.3 | 0.00 | Dec 5, 2023 | Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information. | ||
| CVE-2023-42542 | Low | 0.21 | 3.3 | 0.00 | Nov 7, 2023 | Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the device. | ||
| CVE-2023-30730 | Low | 0.21 | 3.3 | 0.00 | Sep 6, 2023 | Implicit intent hijacking vulnerability in Camera prior to versions 11.0.16.43 in Android 11, 12.1.00.30, 12.0.07.53, 12.1.03.10 in Android 12, and 13.0.01.43, 13.1.00.83 in Android 13 allows local attacker to access specific file. | ||
| CVE-2023-30703 | Low | 0.21 | 3.3 | 0.00 | Aug 10, 2023 | Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information. | ||
| CVE-2023-30648 | Low | 0.21 | 3.3 | 0.00 | Jul 6, 2023 | Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system. | ||
| CVE-2023-21452 | Low | 0.21 | 3.3 | 0.00 | Mar 16, 2023 | Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device. | ||
| CVE-2023-21436 | Low | 0.21 | 3.3 | 0.00 | Feb 9, 2023 | Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID. | ||
| CVE-2023-21431 | Low | 0.21 | 3.3 | 0.00 | Feb 9, 2023 | Improper input validation in Bixby Vision prior to version 3.7.70.17 allows attacker to access data of Bixby Vision. |
- risk 0.25cvss 3.9epss 0.00
This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phones. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The…
- risk 0.25cvss 3.9epss 0.00
Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view.
- risk 0.25cvss 3.9epss 0.00
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
- risk 0.25cvss 3.8epss 0.00
Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.
- risk 0.25cvss 3.9epss 0.00
PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
- risk 0.25cvss 3.9epss 0.00
PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.
- risk 0.25cvss 3.9epss 0.00
PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent.
- risk 0.25cvss 3.9epss 0.00
Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox.
- risk 0.25cvss 3.8epss 0.00
Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.
- risk 0.25cvss 3.9epss 0.00
A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
- risk 0.24cvss 3.7epss 0.00
An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not…
- risk 0.24cvss 3.7epss 0.00
An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not…
- risk 0.24cvss 3.7epss 0.00
A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.
- risk 0.24cvss 3.7epss 0.01
Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.
- risk 0.23cvss 3.5epss 0.00
An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when…
- risk 0.23cvss 3.5epss 0.00
Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-1033.2 and before allows attackers to cause a denial of service via WPS attack tools.
- risk 0.23cvss 3.6epss 0.00
Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.
- risk 0.23cvss 3.6epss 0.00
Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permission.
- risk 0.23cvss 3.5epss 0.00
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not block access to Quick Panel and notifications. The Samsung ID is SVE-2020-17187 (June 2020).
- risk 0.23cvss 3.5epss 0.00
An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does not block Quick Panel access to Music Share. The Samsung ID is SVE-2020-17145 (June 2020).
- risk 0.22cvss 4.4epss 0.00
Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.
- risk 0.22cvss 4.4epss 0.00
Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.
- risk 0.21cvss 3.3epss 0.00
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
- risk 0.21cvss 3.3epss 0.00
Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.
- risk 0.21cvss 3.3epss 0.00
External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.
- risk 0.21cvss 3.3epss 0.00
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
- risk 0.21cvss 3.3epss 0.00
Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.
- risk 0.21cvss 3.3epss 0.00
Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity with Samsung Email privilege.
- risk 0.21cvss 3.3epss 0.00
Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information.
- risk 0.21cvss 3.3epss 0.00
Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.
- risk 0.21cvss 3.3epss 0.00
Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.
- risk 0.21cvss 3.3epss 0.00
Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.
- risk 0.21cvss 3.2epss 0.00
Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.
- risk 0.21cvss 3.3epss 0.00
Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
- risk 0.21cvss 3.3epss 0.00
Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.
- risk 0.21cvss 3.3epss 0.00
Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.
- risk 0.21cvss 3.3epss 0.00
The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.
- risk 0.21cvss 3.3epss 0.00
Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.21cvss 3.3epss 0.00
Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information.
- risk 0.21cvss 3.3epss 0.00
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
- risk 0.21cvss 3.3epss 0.00
Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information.
- risk 0.21cvss 3.3epss 0.00
Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the device.
- risk 0.21cvss 3.3epss 0.00
Implicit intent hijacking vulnerability in Camera prior to versions 11.0.16.43 in Android 11, 12.1.00.30, 12.0.07.53, 12.1.03.10 in Android 12, and 13.0.01.43, 13.1.00.83 in Android 13 allows local attacker to access specific file.
- risk 0.21cvss 3.3epss 0.00
Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.
- risk 0.21cvss 3.3epss 0.00
Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.
- risk 0.21cvss 3.3epss 0.00
Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
- risk 0.21cvss 3.3epss 0.00
Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
- risk 0.21cvss 3.3epss 0.00
Improper input validation in Bixby Vision prior to version 3.7.70.17 allows attacker to access data of Bixby Vision.
Page 42 of 47