VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2021-25351LowMar 25, 2021
    risk 0.21cvss 3.2epss 0.00

    Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.

  • CVE-2021-25333LowMar 4, 2021
    risk 0.21cvss 3.2epss 0.00

    Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.

  • CVE-2021-25332LowMar 4, 2021
    risk 0.21cvss 3.2epss 0.00

    Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition.

  • CVE-2021-25331LowMar 4, 2021
    risk 0.21cvss 3.2epss 0.00

    Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.

  • CVE-2018-21074LowApr 8, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Samsung mobile devices with M(6.x) (Exynos or Qualcomm chipsets) software. There is information disclosure from a Trustlet via the debug log. The Samsung ID is SVE-2017-10638 (April 2018).

  • CVE-2018-21043LowApr 8, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 9810 chipsets) software. There is information disclosure about a kernel pointer in the g2d_drv driver because of logging. The Samsung ID is SVE-2018-13035 (December 2018).

  • CVE-2019-20625LowMar 24, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-2018-13427 (February 2019).

  • CVE-2019-20623LowMar 24, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. Gallery has uninitialized memory disclosure. The Samsung ID is SVE-2018-13060 (February 2019).

  • CVE-2019-6331LowJan 9, 2020
    risk 0.21cvss 3.3epss 0.00

    An issue was found in Samsung Mobile Print (Android) versions prior to 4.08.007. A potential security vulnerability caused by incomplete obfuscation of application configuration information.

  • CVE-2016-2567LowApr 13, 2017
    risk 0.21cvss 3.3epss 0.00

    secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the…

  • CVE-2016-2565LowApr 13, 2017
    risk 0.21cvss 3.3epss 0.00

    Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages, aka SVE-2015-5081.

  • CVE-2023-29092LowMay 9, 2023
    risk 0.20cvss 3.1epss 0.00

    An issue was discovered in Exynos Mobile Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, and Exynos 1080. Binding of a wrong resource can occur due to improper handling of parameters while binding a network interface.

  • CVE-2021-25454LowSep 9, 2021
    risk 0.20cvss 3.1epss 0.00

    OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.

  • CVE-2021-25376LowApr 9, 2021
    risk 0.20cvss 3.1epss 0.01

    An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.

  • CVE-2022-27834LowApr 11, 2022
    risk 0.19cvss 2.9epss 0.00

    Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions.

  • CVE-2022-27831LowApr 11, 2022
    risk 0.19cvss 2.9epss 0.00

    Improper boundary check in sflvd_rdbuf_bits of libsflvextractor prior to SMR Apr-2022 Release 1 allows attackers to read out of bounds memory.

  • CVE-2023-37366LowSep 14, 2026
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123,…

  • CVE-2026-33968LowSep 14, 2026
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.

  • CVE-2026-33967LowSep 14, 2026
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, an out-of-bounds array access vulnerability in the error-handling path leads to memory corruption.

  • CVE-2026-33966LowSep 14, 2026
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. An information Leak occurs in the camera driver due to Insertion of Sensitive Information Into Debugging Code.

  • CVE-2026-33962LowSep 14, 2026
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.

  • CVE-2026-33960LowSep 14, 2026
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 1580, 1680, W920, W930, and W1000. . A malformed ioctl command to the Wi-Fi interface device can lead to improper buffer size allocation, resulting in an out-of-bounds write and…

  • CVE-2026-33956LowSep 14, 2026
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, and 2500. Sending a malformed message to the test_msg sysfs entry causes an out-of-bounds write, leading to denial of service.

  • CVE-2026-23786LowSep 14, 2026
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A TOCTOU race condition in the Exynos DRM HDR Driver leads to a heap overflow, causing a kernel crash.

  • CVE-2026-21014LowApr 13, 2026
    risk 0.18cvss 2.8epss 0.00

    Improper access control in Samsung Camera prior to version 16.5.00.28 allows local attacker to access location data. User interaction is required for triggering this vulnerability.

  • CVE-2024-53921LowDec 3, 2024
    risk 0.18cvss 2.8epss 0.00

    An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.

  • CVE-2022-36877LowSep 9, 2022
    risk 0.18cvss 2.8epss 0.00

    Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.

  • CVE-2022-22283LowJan 10, 2022
    risk 0.18cvss 2.8epss 0.00

    Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging out from Samsung Health App.

  • CVE-2021-25336LowMar 4, 2021
    risk 0.18cvss 2.8epss 0.00

    Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.

  • CVE-2026-21006LowApr 13, 2026
    risk 0.16cvss 2.4epss 0.00

    Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.

  • CVE-2026-20989LowMar 16, 2026
    risk 0.16cvss 2.4epss 0.00

    Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.

  • CVE-2025-21046LowOct 10, 2025
    risk 0.16cvss 2.4epss 0.00

    Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list.

  • CVE-2024-49414LowDec 3, 2024
    risk 0.16cvss 2.4epss 0.00

    Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.

  • CVE-2024-34682LowNov 6, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi password in Maintenance Mode.

  • CVE-2024-34675LowNov 6, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to unlocked screen.

  • CVE-2024-34649LowSep 4, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.

  • CVE-2024-20855LowMay 7, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.

  • CVE-2024-20828LowFeb 6, 2024
    risk 0.16cvss 2.4epss 0.00

    Improper authorization verification vulnerability in Samsung Internet prior to version 24.0 allows physical attackers to access files downloaded in SecretMode without proper authentication.

  • CVE-2023-21512LowJun 28, 2023
    risk 0.16cvss 2.4epss 0.00

    Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.

  • CVE-2023-21454LowMar 16, 2023
    risk 0.16cvss 2.4epss 0.00

    Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.

  • CVE-2022-33720LowAug 5, 2022
    risk 0.16cvss 2.4epss 0.00

    Improper authentication vulnerability in AppLock prior to SMR Aug-2022 Release 1 allows physical attacker to access Chrome locked by AppLock via new tap shortcut.

  • CVE-2022-33706LowJul 12, 2022
    risk 0.16cvss 2.4epss 0.00

    Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access the pictures using S Pen air gesture.

  • CVE-2022-30721LowJun 7, 2022
    risk 0.16cvss 2.5epss 0.00

    Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

  • CVE-2022-30720LowJun 7, 2022
    risk 0.16cvss 2.5epss 0.00

    Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

  • CVE-2022-30719LowJun 7, 2022
    risk 0.16cvss 2.5epss 0.00

    Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

  • CVE-2022-30709LowJun 7, 2022
    risk 0.16cvss 2.5epss 0.00

    Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1 allows attackers to trigger crash.

  • CVE-2021-25513LowDec 8, 2021
    risk 0.16cvss 2.4epss 0.00

    An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.

  • CVE-2021-25486LowOct 6, 2021
    risk 0.16cvss 2.5epss 0.00

    Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log.

  • CVE-2021-25409LowJun 11, 2021
    risk 0.16cvss 2.4epss 0.00

    Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.

  • CVE-2021-25335LowMar 4, 2021
    risk 0.16cvss 2.5epss 0.00

    Improper lockscreen status check in cocktailbar service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows unauthenticated users to access hidden notification contents over the lockscreen in specific condition.

Page 44 of 47