VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2022-1230LowMar 28, 2023
    risk 0.25cvss 3.9epss 0.00

    This vulnerability allows local attackers to execute arbitrary code on affected installations of Samsung Galaxy S21 prior to 4.5.40.5 phones. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The…

  • CVE-2022-39910LowDec 8, 2022
    risk 0.25cvss 3.9epss 0.00

    Improper access control vulnerability in Samsung Pass prior to version 4.0.06.7 allow physical attackers to access data of Samsung Pass on a certain state of an unlocked device using pop-up view.

  • CVE-2022-36851LowSep 9, 2022
    risk 0.25cvss 3.9epss 0.00

    Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.

  • CVE-2022-24001LowFeb 11, 2022
    risk 0.25cvss 3.8epss 0.00

    Information disclosure vulnerability in Edge Panel prior to Android S(12) allows physical attackers to access screenshot in clipboard via Edge Panel.

  • CVE-2022-24000LowFeb 11, 2022
    risk 0.25cvss 3.9epss 0.00

    PendingIntent hijacking vulnerability in DataUsageReminderReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.

  • CVE-2022-23999LowFeb 11, 2022
    risk 0.25cvss 3.9epss 0.00

    PendingIntent hijacking vulnerability in CpaReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission in KnoxPrivacyNoticeReceiver via implicit Intent.

  • CVE-2022-23427LowFeb 11, 2022
    risk 0.25cvss 3.9epss 0.00

    PendingIntent hijacking vulnerability in KnoxPrivacyNoticeReceiver prior to SMR Feb-2022 Release 1 allows local attackers to access media files without permission via implicit Intent.

  • CVE-2022-22287LowJan 10, 2022
    risk 0.25cvss 3.9epss 0.00

    Abitrary file access vulnerability in Samsung Email prior to 6.1.60.16 allows attacker to read isolated data in sandbox.

  • CVE-2021-25527LowDec 8, 2021
    risk 0.25cvss 3.8epss 0.00

    Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.

  • CVE-2021-25475LowOct 6, 2021
    risk 0.25cvss 3.9epss 0.00

    A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2023-50804LowJun 5, 2024
    risk 0.24cvss 3.7epss 0.00

    An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not…

  • CVE-2023-50803LowJun 5, 2024
    risk 0.24cvss 3.7epss 0.00

    An issue was discovered in Samsung Mobile Processor, and Modem Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos Modem 5123, Exynos Modem 5300. The baseband software does not…

  • CVE-2021-25471LowOct 6, 2021
    risk 0.24cvss 3.7epss 0.00

    A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.

  • CVE-2021-25367LowMar 25, 2021
    risk 0.24cvss 3.7epss 0.01

    Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.

  • CVE-2026-33970LowSep 14, 2026
    risk 0.23cvss 3.5epss 0.00

    An issue was discovered in NR RRC and L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 1680, W920, W930, W1000, and Modem 5410. In the 5G baseband, a NULL Pointer Dereference occurs when…

  • CVE-2023-41270LowNov 8, 2023
    risk 0.23cvss 3.5epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Samsung Smart TV UE40D7000 version T-GAPDEUC-1033.2 and before allows attackers to cause a denial of service via WPS attack tools.

  • CVE-2022-39892LowNov 9, 2022
    risk 0.23cvss 3.6epss 0.00

    Improper access control in Samsung Pass prior to version 4.0.05.1 allows attackers to unauthenticated access via keep open feature.

  • CVE-2022-39863LowOct 7, 2022
    risk 0.23cvss 3.6epss 0.00

    Intent redirection vulnerability in Samsung Account prior to version 13.5.01.3 allows attackers to access content providers without permission.

  • CVE-2020-13838LowJun 4, 2020
    risk 0.23cvss 3.5epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not block access to Quick Panel and notifications. The Samsung ID is SVE-2020-17187 (June 2020).

  • CVE-2020-13837LowJun 4, 2020
    risk 0.23cvss 3.5epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does not block Quick Panel access to Music Share. The Samsung ID is SVE-2020-17145 (June 2020).

  • CVE-2026-91826MedSep 15, 2026
    risk 0.22cvss 4.4epss 0.00

    Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.

  • CVE-2026-49509MedSep 4, 2026
    risk 0.22cvss 4.4epss 0.00

    Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.

  • CVE-2026-21062LowAug 10, 2026
    risk 0.21cvss 3.3epss 0.00

    Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

  • CVE-2026-21027LowJun 5, 2026
    risk 0.21cvss 3.3epss 0.00

    Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

  • CVE-2026-21012LowApr 13, 2026
    risk 0.21cvss 3.3epss 0.00

    External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.

  • CVE-2026-20992LowMar 16, 2026
    risk 0.21cvss 3.3epss 0.00

    Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.

  • CVE-2026-20972LowJan 9, 2026
    risk 0.21cvss 3.3epss 0.00

    Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.

  • CVE-2025-21077LowNov 5, 2025
    risk 0.21cvss 3.3epss 0.00

    Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity with Samsung Email privilege.

  • CVE-2025-21024LowAug 6, 2025
    risk 0.21cvss 3.3epss 0.00

    Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information.

  • CVE-2025-21023LowAug 6, 2025
    risk 0.21cvss 3.3epss 0.00

    Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.

  • CVE-2025-21022LowAug 6, 2025
    risk 0.21cvss 3.3epss 0.00

    Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.

  • CVE-2025-20977LowMay 7, 2025
    risk 0.21cvss 3.3epss 0.00

    Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

  • CVE-2025-20895LowFeb 4, 2025
    risk 0.21cvss 3.2epss 0.00

    Authentication Bypass Using an Alternate Path in Galaxy Store prior to version 4.5.87.6 allows physical attackers to install arbitrary applications to bypass restrictions of Setupwizard.

  • CVE-2024-34671LowOct 8, 2024
    risk 0.21cvss 3.3epss 0.00

    Use of implicit intent for sensitive communication in translation혻in Samsung Internet prior to version 26.0.3.1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

  • CVE-2024-34640LowSep 4, 2024
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.

  • CVE-2024-34602LowJul 8, 2024
    risk 0.21cvss 3.3epss 0.00

    Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.

  • CVE-2024-20836LowMar 5, 2024
    risk 0.21cvss 3.3epss 0.00

    Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.

  • CVE-2024-20834LowMar 5, 2024
    risk 0.21cvss 3.3epss 0.00

    The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.

  • CVE-2024-20810LowFeb 6, 2024
    risk 0.21cvss 3.3epss 0.00

    Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-20807LowJan 4, 2024
    risk 0.21cvss 3.3epss 0.00

    Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information.

  • CVE-2024-20805LowJan 4, 2024
    risk 0.21cvss 3.3epss 0.00

    Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.

  • CVE-2023-42572LowDec 5, 2023
    risk 0.21cvss 3.3epss 0.00

    Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information.

  • CVE-2023-42556LowDec 5, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.

  • CVE-2023-42542LowNov 7, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in Samsung Push Service prior to 3.4.10 allows local attackers to get register ID to identify the device.

  • CVE-2023-30730LowSep 6, 2023
    risk 0.21cvss 3.3epss 0.00

    Implicit intent hijacking vulnerability in Camera prior to versions 11.0.16.43 in Android 11, 12.1.00.30, 12.0.07.53, 12.1.03.10 in Android 12, and 13.0.01.43, 13.1.00.83 in Android 13 allows local attacker to access specific file.

  • CVE-2023-30703LowAug 10, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.

  • CVE-2023-30648LowJul 6, 2023
    risk 0.21cvss 3.3epss 0.00

    Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.

  • CVE-2023-21452LowMar 16, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.

  • CVE-2023-21436LowFeb 9, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.

  • CVE-2023-21431LowFeb 9, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper input validation in Bixby Vision prior to version 3.7.70.17 allows attacker to access data of Bixby Vision.

Page 42 of 47