Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39915 | Low | 0.21 | 3.3 | 0.00 | Dec 8, 2022 | Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent. | ||
| CVE-2022-39904 | Low | 0.21 | 3.3 | 0.00 | Dec 8, 2022 | Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log. | ||
| CVE-2022-39893 | Low | 0.21 | 3.3 | 0.00 | Nov 9, 2022 | Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log. | ||
| CVE-2022-39864 | Low | 0.21 | 3.3 | 0.00 | Oct 7, 2022 | Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent. | ||
| CVE-2022-39850 | Low | 0.21 | 3.3 | 0.00 | Oct 7, 2022 | Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data. | ||
| CVE-2022-39849 | Low | 0.21 | 3.3 | 0.00 | Oct 7, 2022 | Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data. | ||
| CVE-2022-36878 | Low | 0.21 | 3.3 | 0.00 | Sep 9, 2022 | Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log. | ||
| CVE-2022-36853 | Low | 0.21 | 3.3 | 0.00 | Sep 9, 2022 | Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information. | ||
| CVE-2022-36835 | Low | 0.21 | 3.3 | 0.00 | Aug 5, 2022 | Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to access arbitrary files. | ||
| CVE-2022-36834 | Low | 0.21 | 3.3 | 0.00 | Aug 5, 2022 | Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction. | ||
| CVE-2022-33726 | Low | 0.21 | 3.3 | 0.00 | Aug 5, 2022 | Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity. | ||
| CVE-2022-33724 | Low | 0.21 | 3.3 | 0.00 | Aug 5, 2022 | Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log. | ||
| CVE-2022-33705 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission. | ||
| CVE-2022-33701 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent. | ||
| CVE-2022-33698 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log. | ||
| CVE-2022-33697 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log. | ||
| CVE-2022-33688 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log. | ||
| CVE-2022-33687 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log. | ||
| CVE-2022-30753 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission. | ||
| CVE-2022-30752 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action. | ||
| CVE-2022-30751 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action. | ||
| CVE-2022-30750 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected. | ||
| CVE-2022-30749 | Low | 0.21 | 3.3 | 0.00 | Jun 7, 2022 | Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity. | ||
| CVE-2022-30742 | Low | 0.21 | 3.3 | 0.00 | Jun 7, 2022 | Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log. | ||
| CVE-2022-30741 | Low | 0.21 | 3.3 | 0.00 | Jun 7, 2022 | Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log. | ||
| CVE-2022-30729 | Low | 0.21 | 3.3 | 0.00 | Jun 7, 2022 | Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner. | ||
| CVE-2022-27839 | Low | 0.21 | 3.3 | 0.01 | Apr 11, 2022 | Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials. | ||
| CVE-2022-27576 | Low | 0.21 | 3.3 | 0.00 | Apr 11, 2022 | Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission | ||
| CVE-2022-27575 | Low | 0.21 | 3.3 | 0.00 | Apr 11, 2022 | Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission. | ||
| CVE-2022-25833 | Low | 0.21 | 3.3 | 0.00 | Apr 11, 2022 | Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission. | ||
| CVE-2022-25821 | Low | 0.21 | 3.3 | 0.00 | Mar 10, 2022 | Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read. | ||
| CVE-2022-23994 | Low | 0.21 | 3.3 | 0.00 | Feb 11, 2022 | An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission. | ||
| CVE-2021-25514 | Low | 0.21 | 3.3 | 0.00 | Dec 8, 2021 | An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information. | ||
| CVE-2021-25505 | Low | 0.21 | 3.3 | 0.01 | Nov 5, 2021 | Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked. | ||
| CVE-2021-25465 | Low | 0.21 | 3.3 | 0.00 | Sep 9, 2021 | An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack. | ||
| CVE-2021-25464 | Low | 0.21 | 3.3 | 0.00 | Sep 9, 2021 | An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak. | ||
| CVE-2021-25462 | Low | 0.21 | 3.3 | 0.00 | Sep 9, 2021 | NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption. | ||
| CVE-2021-25458 | Low | 0.21 | 3.3 | 0.00 | Sep 9, 2021 | NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption. | ||
| CVE-2021-25455 | Low | 0.21 | 3.3 | 0.00 | Sep 9, 2021 | OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file. | ||
| CVE-2021-25451 | Low | 0.21 | 3.3 | 0.00 | Sep 9, 2021 | A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data. | ||
| CVE-2021-25439 | Low | 0.21 | 3.3 | 0.00 | Jul 8, 2021 | Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview. | ||
| CVE-2021-25432 | Low | 0.21 | 3.3 | 0.00 | Jul 8, 2021 | Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data. | ||
| CVE-2021-25404 | Low | 0.21 | 3.3 | 0.00 | Jun 11, 2021 | Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log. | ||
| CVE-2021-25403 | Low | 0.21 | 3.3 | 0.00 | Jun 11, 2021 | Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component. | ||
| CVE-2021-25402 | Low | 0.21 | 3.3 | 0.00 | Jun 11, 2021 | Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information. | ||
| CVE-2021-25398 | Low | 0.21 | 3.3 | 0.00 | Jun 11, 2021 | Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access contacts. | ||
| CVE-2021-25377 | Low | 0.21 | 3.3 | 0.00 | Apr 9, 2021 | Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action. | ||
| CVE-2021-25368 | Low | 0.21 | 3.3 | 0.01 | Mar 25, 2021 | Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed. | ||
| CVE-2021-25366 | Low | 0.21 | 3.2 | 0.00 | Mar 25, 2021 | Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication. | ||
| CVE-2021-25354 | Low | 0.21 | 3.3 | 0.00 | Mar 25, 2021 | Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink. |
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in Calendar prior to versions 11.6.08.0 in Android Q(10), 12.2.11.3000 in Android R(11), 12.3.07.2000 in Android S(12), and 12.4.02.0 in Android T(13) allows attackers to access sensitive information via implicit intent.
- risk 0.21cvss 3.3epss 0.00
Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.
- risk 0.21cvss 3.3epss 0.00
Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in WifiSetupLaunchHelper in SmartThings prior to version 1.7.89.25 allows attackers to access sensitive information via implicit intent.
- risk 0.21cvss 3.3epss 0.00
Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
- risk 0.21cvss 3.3epss 0.00
Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
- risk 0.21cvss 3.3epss 0.00
Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log.
- risk 0.21cvss 3.3epss 0.00
Intent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.
- risk 0.21cvss 3.3epss 0.00
Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to access arbitrary files.
- risk 0.21cvss 3.3epss 0.00
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction.
- risk 0.21cvss 3.3epss 0.00
Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.
- risk 0.21cvss 3.3epss 0.00
Exposure of Sensitive Information in Samsung Dialer application?prior to SMR Aug-2022 Release 1 allows local attackers to access ICCID via log.
- risk 0.21cvss 3.3epss 0.00
Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Jul-2022 Release 1 allows attacker to call PowerManaer.goToSleep method which is protected by system permission by sending braodcast intent.
- risk 0.21cvss 3.3epss 0.00
Exposure of Sensitive Information in Telecom application prior to SMR Jul-2022 Release 1 allows local attackers to access ICCID via log.
- risk 0.21cvss 3.3epss 0.00
Sensitive information exposure vulnerability in ImsServiceSwitchBase in ImsCore prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.
- risk 0.21cvss 3.3epss 0.00
Sensitive information exposure vulnerability in EventType in SecTelephonyProvider prior to SMR Jul-2022 Release 1 allows local attackers with log access permission to get IMSI through device log.
- risk 0.21cvss 3.3epss 0.00
Exposure of Sensitive Information in telephony-common.jar prior to SMR Jul-2022 Release 1 allows local attackers to access IMSI via log.
- risk 0.21cvss 3.3epss 0.00
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_STATE_CHANGED action.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in sendDHCPACKBroadcast function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected by using WIFI_AP_STA_DHCPACK_EVENT action.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in updateLastConnectedClientInfo function of SemWifiApClient prior to SMR Jul-2022 Release 1 allows attacker to access wifi ap client mac address that connected.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.
- risk 0.21cvss 3.3epss 0.00
Sensitive information exposure vulnerability in FmmExtraOperation of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permissio to get sim card information through device log.
- risk 0.21cvss 3.3epss 0.00
Sensitive information exposure vulnerability in SimChangeAlertManger of Find My Mobile prior to 7.2.24.12 allows local attackers with log access permission to get sim card information through device log.
- risk 0.21cvss 3.3epss 0.00
Implicit Intent hijacking vulnerability in Settings prior to SMR Jun-2022 Release 1 allows attackers to get Wi-Fi SSID and password via a malicious QR code scanner.
- risk 0.21cvss 3.3epss 0.01
Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.
- risk 0.21cvss 3.3epss 0.00
Information exposure vulnerability in Samsung DeX Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission
- risk 0.21cvss 3.3epss 0.00
Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.
- risk 0.21cvss 3.3epss 0.00
Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission.
- risk 0.21cvss 3.3epss 0.00
Improper use of SMS buffer pointer in Shannon baseband prior to SMR Mar-2022 Release 1 allows OOB read.
- risk 0.21cvss 3.3epss 0.00
An Improper access control vulnerability in StBedtimeModeReceiver in Wear OS 3.0 prior to Firmware update Feb-2022 Release allows untrusted applications to change bedtime mode without a proper permission.
- risk 0.21cvss 3.3epss 0.00
An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.
- risk 0.21cvss 3.3epss 0.01
Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.
- risk 0.21cvss 3.3epss 0.00
An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-middle attack.
- risk 0.21cvss 3.3epss 0.00
An improper file management vulnerability in SamsungCapture prior to version 4.8.02 allows sensitive information leak.
- risk 0.21cvss 3.3epss 0.00
NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
- risk 0.21cvss 3.3epss 0.00
NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory corruption.
- risk 0.21cvss 3.3epss 0.00
OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.
- risk 0.21cvss 3.3epss 0.00
A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause arbitrary webpage loading in webview.
- risk 0.21cvss 3.3epss 0.00
Information exposure vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to access chat data.
- risk 0.21cvss 3.3epss 0.00
Information Exposure vulnerability in SmartThings prior to version 1.7.64.21 allows attacker to access user information via log.
- risk 0.21cvss 3.3epss 0.00
Intent redirection vulnerability in Samsung Account prior to version 10.8.0.4 in Android P(9.0) and below, and 12.2.0.9 in Android Q(10.0) and above allows attacker to access contacts and file provider using SettingWebView component.
- risk 0.21cvss 3.3epss 0.00
Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information.
- risk 0.21cvss 3.3epss 0.00
Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access contacts.
- risk 0.21cvss 3.3epss 0.00
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.
- risk 0.21cvss 3.3epss 0.01
Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.
- risk 0.21cvss 3.2epss 0.00
Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.
- risk 0.21cvss 3.3epss 0.00
Improper input check in Samsung Internet prior to version 13.2.1.46 allows attackers to launch non-exported activity in Samsung Browser via malicious deeplink.
Page 43 of 47