VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,262 total · sorted by risk
  • CVE-2018-21073LowApr 8, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) and O(8.0) (Galaxy S9+, Galaxy S9, Galaxy S8+, Galaxy S8, Note 8). There is access to Clipboard content in the locked state via the Edge panel. The Samsung ID is SVE-2017-10748 (May 2018).

  • CVE-2018-21046LowApr 8, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. There is clipboard Data Exposure via the Emergency Dialer upon connecting a USB device. The Samsung ID is SVE-2018-12911 (November 2018).

  • CVE-2020-11606LowApr 8, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) software. Information about application preview (in the Secure Folder) leaks on a locked device. The Samsung ID is SVE-2019-16463 (April 2020).

  • CVE-2020-11602LowApr 8, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Google Assistant leaks clipboard contents on a locked device. The Samsung ID is SVE-2019-16558 (April 2020).

  • CVE-2017-18673LowApr 7, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x) software. An attacker can disable the Location service on a locked device, making it impossible for the rightful owner to find a stolen device. The Samsung ID is SVE-2017-8524 (May 2017).

  • CVE-2016-11027LowApr 7, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.0) software. In the Shade Locked state, a physically proximate attacker can read notifications on the lock screen. The Samsung ID is SVE-2016-7132 (December 2016).

  • CVE-2019-20598LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs are SVE-2018-12896, SVE-2018-12897 (May 2019).

  • CVE-2019-20595LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Quick Panel allows enabling or disabling the Bluetooth stack without authentication. The Samsung ID is SVE-2019-14545 (July 2019).

  • CVE-2019-20579LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery allows attackers to enable Location information sharing from the lock screen. The Samsung ID is SVE-2019-14462 (August 2019).

  • CVE-2019-20559LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of photos on the lock screen. The Samsung ID is SVE-2019-15055 (October 2019).

  • CVE-2020-10830LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can view notifications by entering many PINs in Lockdown mode. The Samsung ID is SVE-2019-16590 (March 2020).

  • CVE-2019-20534LowMar 24, 2020
    risk 0.16cvss 2.4epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view home-screen wallpaper by adjusting the brightness of a locked screen. The Samsung ID is SVE-2019-15540 (December 2019).

  • CVE-2023-21450LowFeb 9, 2023
    risk 0.15cvss 2.3epss 0.00

    Missing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner's widget without authorization via gesture setting.

  • CVE-2022-39906LowDec 8, 2022
    risk 0.15cvss 2.3epss 0.00

    Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.

  • CVE-2022-33716LowAug 5, 2022
    risk 0.15cvss 2.3epss 0.00

    An absence of variable initialization in ICCC TA prior to SMR Aug-2022 Release 1 allows local attacker to read uninitialized memory.

  • CVE-2022-33686LowJul 12, 2022
    risk 0.15cvss 2.3epss 0.00

    Exposure of Sensitive Information in GsmAlarmManager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

  • CVE-2021-25491LowOct 6, 2021
    risk 0.15cvss 2.3epss 0.00

    A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.

  • CVE-2021-25389LowJun 11, 2021
    risk 0.15cvss 2.3epss 0.00

    Improper running task check in S Secure prior to SMR MAY-2021 Release 1 allows attackers to use locked app without authentication.

  • CVE-2023-21438LowFeb 9, 2023
    risk 0.14cvss 2.1epss 0.00

    Improper logic in HomeScreen prior to SMR Feb-2023 Release 1 allows physical attacker to access App preview protected by Secure Folder.

  • CVE-2022-28794LowJun 7, 2022
    risk 0.14cvss 2.2epss 0.00

    Sensitive information exposure in low-battery dumpstate log prior to SMR Jun-2022 Release 1 allows local attackers to get SIM card information.

  • CVE-2022-24924LowFeb 11, 2022
    risk 0.14cvss 2.2epss 0.01

    An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.

  • CVE-2021-25348LowMar 4, 2021
    risk 0.14cvss 2.1epss 0.00

    Improper permission grant check in Samsung Internet prior to version 13.0.1.60 allows access to files in internal storage without authorized STORAGE permission.

  • CVE-2024-49417LowDec 3, 2024
    risk 0.13cvss 2.0epss 0.00

    Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.

  • CVE-2023-40218LowSep 12, 2023
    risk 0.13cvss 2.0epss 0.00

    An issue was discovered in the NPU kernel driver in Samsung Exynos Mobile Processor 9820, 980, 2100, 2200, 1280, and 1380. An integer overflow can bypass detection of error cases via a crafted application.

  • CVE-2023-40353LowSep 8, 2023
    risk 0.13cvss 2.0epss 0.00

    An issue was discovered in Exynos Mobile Processor 980 and 2100. An integer overflow at a buffer index can prevent the execution of requested services via a crafted application.

  • CVE-2023-37377LowSep 8, 2023
    risk 0.13cvss 2.0epss 0.00

    An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor (Exynos 980, Exynos 850, Exynos 2100, and Exynos W920). Improper handling of length parameter inconsistency can cause incorrect packet filtering.

  • CVE-2022-33700LowJul 12, 2022
    risk 0.13cvss 2.0epss 0.00

    Exposure of Sensitive Information in putDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

  • CVE-2022-33699LowJul 12, 2022
    risk 0.13cvss 2.0epss 0.00

    Exposure of Sensitive Information in getDsaSimImsi in TelephonyUI prior to SMR Jul-2022 Release 1 allows local attacker to access imsi via log.

  • CVE-2022-33693LowJul 12, 2022
    risk 0.13cvss 2.0epss 0.00

    Exposure of Sensitive Information in CID Manager prior to SMR Jul-2022 Release 1 allows local attacker to access iccid via log.

  • CVE-2022-25831LowApr 11, 2022
    risk 0.13cvss 2.0epss 0.00

    Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access secured data in certain conditions.

  • CVE-2021-25525LowDec 8, 2021
    risk 0.13cvss 2.0epss 0.00

    Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.

  • CVE-2021-25350LowMar 25, 2021
    risk 0.13cvss 2.0epss 0.00

    Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.

  • CVE-2022-36876LowSep 9, 2022
    risk 0.12cvss 1.8epss 0.00

    Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical attackers to access account list without authentication.

  • CVE-2022-36857LowSep 9, 2022
    risk 0.12cvss 1.9epss 0.00

    Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.

  • CVE-2022-36852LowSep 9, 2022
    risk 0.12cvss 1.9epss 0.00

    Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local attacker to access internal application data.

  • CVE-2022-30728LowJun 7, 2022
    risk 0.12cvss 1.9epss 0.00

    Information exposure vulnerability in ScanPool prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

  • CVE-2022-30714LowJun 7, 2022
    risk 0.12cvss 1.9epss 0.00

    Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local attackers to get MAC address information.

  • CVE-2022-25830LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy Watch3 Plugin prior to version 2.2.09.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25829LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Watch Active2 Plugin prior to version 2.2.08.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25828LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Watch Active Plugin prior to version 2.2.07.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25827LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25826LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy S3 Plugin prior to version 2.2.03.22012751 allows attacker to access password information of connected WiFiAp in the log

  • CVE-2022-25823LowMar 10, 2022
    risk 0.12cvss 1.9epss 0.00

    Information Exposure vulnerability in Galaxy Watch Plugin prior to version 2.2.05.220126741 allows attackers to access user information in log.

  • CVE-2012-4333Aug 14, 2012
    risk 0.08cvss epss 0.60

    Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary code via a long string in the fname parameter. NOTE: some of…

  • CVE-2013-3585Aug 28, 2013
    risk 0.05cvss epss 0.24

    Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page.

  • CVE-2015-7897Nov 16, 2015
    risk 0.04cvss epss 0.07

    The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remote attackers to gain privileges or cause a denial of service (memory corruption) via a crafted BMP image file.

  • CVE-2015-0555Feb 24, 2015
    risk 0.04cvss epss 0.06

    Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitrary code via a long string in the first argument to the (1) ReadConfigValue or (2) WriteConfigValue function.

  • CVE-2012-6429Apr 4, 2014
    risk 0.04cvss epss 0.15

    Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a long string to the password argument.

  • CVE-2013-3586Aug 28, 2013
    risk 0.04cvss epss 0.11

    Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.

  • CVE-2012-4334Aug 14, 2012
    risk 0.04cvss epss 0.07

    The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party…