VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2022-39915LowDec 8, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent.

  • CVE-2022-39904LowDec 8, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.

  • CVE-2022-39893LowNov 9, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.

  • CVE-2022-39864LowOct 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.

  • CVE-2022-39850LowOct 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

  • CVE-2022-39849LowOct 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.

  • CVE-2022-36878LowSep 9, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log.

  • CVE-2022-36853LowSep 9, 2022
    risk 0.21cvss 3.3epss 0.00

    Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.

  • CVE-2022-36835LowAug 5, 2022
    risk 0.21cvss 3.3epss 0.00

    Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to access arbitrary files.

  • CVE-2022-36834LowAug 5, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction.

  • CVE-2022-33726LowAug 5, 2022
    risk 0.21cvss 3.3epss 0.00

    Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.

  • CVE-2022-33724LowAug 5, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log.

  • CVE-2022-33705LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.

  • CVE-2022-33701LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.

  • CVE-2022-33698LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.

  • CVE-2022-33697LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

  • CVE-2022-33688LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.

  • CVE-2022-33687LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.

  • CVE-2022-30753LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.

  • CVE-2022-30752LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.

  • CVE-2022-30751LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.

  • CVE-2022-30750LowJul 12, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.

  • CVE-2022-30749LowJun 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.

  • CVE-2022-30742LowJun 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log.

  • CVE-2022-30741LowJun 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log.

  • CVE-2022-30729LowJun 7, 2022
    risk 0.21cvss 3.3epss 0.00

    Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner.

  • CVE-2022-27839LowApr 11, 2022
    risk 0.21cvss 3.3epss 0.01

    Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.

  • CVE-2022-27576LowApr 11, 2022
    risk 0.21cvss 3.3epss 0.00

    Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission

  • CVE-2022-27575LowApr 11, 2022
    risk 0.21cvss 3.3epss 0.00

    Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.

  • CVE-2022-25833LowApr 11, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission.

  • CVE-2022-25821LowMar 10, 2022
    risk 0.21cvss 3.3epss 0.00

    Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.

  • CVE-2022-23994LowFeb 11, 2022
    risk 0.21cvss 3.3epss 0.00

    An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.

  • CVE-2021-25514LowDec 8, 2021
    risk 0.21cvss 3.3epss 0.00

    An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.

  • CVE-2021-25505LowNov 5, 2021
    risk 0.21cvss 3.3epss 0.01

    Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.

  • CVE-2021-25465LowSep 9, 2021
    risk 0.21cvss 3.3epss 0.00

    An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack.

  • CVE-2021-25464LowSep 9, 2021
    risk 0.21cvss 3.3epss 0.00

    An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak.

  • CVE-2021-25462LowSep 9, 2021
    risk 0.21cvss 3.3epss 0.00

    NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.

  • CVE-2021-25458LowSep 9, 2021
    risk 0.21cvss 3.3epss 0.00

    NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.

  • CVE-2021-25455LowSep 9, 2021
    risk 0.21cvss 3.3epss 0.00

    OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.

  • CVE-2021-25451LowSep 9, 2021
    risk 0.21cvss 3.3epss 0.00

    A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.

  • CVE-2021-25439LowJul 8, 2021
    risk 0.21cvss 3.3epss 0.00

    Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.

  • CVE-2021-25432LowJul 8, 2021
    risk 0.21cvss 3.3epss 0.00

    Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data.

  • CVE-2021-25404LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log.

  • CVE-2021-25403LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.

  • CVE-2021-25402LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information.

  • CVE-2021-25398LowJun 11, 2021
    risk 0.21cvss 3.3epss 0.00

    Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access contacts.

  • CVE-2021-25377LowApr 9, 2021
    risk 0.21cvss 3.3epss 0.00

    Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.

  • CVE-2021-25368LowMar 25, 2021
    risk 0.21cvss 3.3epss 0.01

    Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.

  • CVE-2021-25366LowMar 25, 2021
    risk 0.21cvss 3.2epss 0.00

    Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.

  • CVE-2021-25354LowMar 25, 2021
    risk 0.21cvss 3.3epss 0.00

    Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.

Page 43 of 47