VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2018-3895HigAug 28, 2018
    risk 0.57cvss 8.8epss 0.02

    An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 Firmware version 0.20.17. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can…

  • CVE-2018-3893HigAug 27, 2018
    risk 0.57cvss 8.8epss 0.02

    An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading…

  • CVE-2018-3879HigAug 23, 2018
    risk 0.57cvss 8.8epss 0.02

    An exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly parses the user-controlled JSON payload, leading to a JSON…

  • CVE-2018-14908HigAug 3, 2018
    risk 0.57cvss 8.8epss 0.01

    Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupView.sws for a "Print emails sent" action.

  • CVE-2017-3218HigJun 21, 2017
    risk 0.57cvss 8.8epss 0.00

    Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for software updates.

  • CVE-2016-1302HigFeb 7, 2016
    risk 0.57cvss 8.8epss 0.02

    Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3h) and 1.1 before 1.1(1j) and Nexus 9000 ACI Mode switches with software before 11.0(3h) and 11.1 before 11.1(1j) allow remote authenticated users to bypass intended RBAC restrictions via…

  • CVE-2026-21019HigMay 13, 2026
    risk 0.56cvss —epss 0.00

    Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to execute arbitrary code with system privilege.

  • CVE-2025-23107HigJun 3, 2025
    risk 0.56cvss 8.6epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

  • CVE-2025-23103HigJun 3, 2025
    risk 0.56cvss 8.6epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bounds writes.

  • CVE-2024-34657HigSep 4, 2024
    risk 0.56cvss 8.6epss 0.01

    Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.

  • CVE-2022-33719HigAug 5, 2022
    risk 0.56cvss 8.6epss 0.00

    Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

  • CVE-2022-23425HigFeb 11, 2022
    risk 0.56cvss 8.6epss 0.00

    Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.

  • CVE-2021-25374HigApr 9, 2021
    risk 0.56cvss 8.6epss 0.03

    An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.

  • CVE-2018-3909HigAug 24, 2018
    risk 0.56cvss 8.6epss 0.01

    An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests to overwrite the…

  • CVE-2018-3911HigAug 23, 2018
    risk 0.56cvss 8.6epss 0.01

    An exploitable HTTP header injection vulnerability exists in the remote servers of Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The hubCore process listens on port 39500 and relays any unauthenticated message to SmartThings' remote servers, which insecurely…

  • CVE-2025-53966HigJan 5, 2026
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, and 1580. Incorrect Handling of the NL80211 vendor command leads to a buffer overflow during handling of an IOCTL message.

  • CVE-2025-49495HigJan 5, 2026
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in the WiFi driver in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580. Mishandling of an NL80211 vendor command leads to a buffer overflow.

  • CVE-2023-21480HigSep 3, 2025
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2025-20979HigMay 7, 2025
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.

  • CVE-2024-34620HigAug 7, 2024
    risk 0.55cvss 8.4epss 0.00

    Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.

  • CVE-2023-50806HigJul 9, 2024
    risk 0.55cvss 8.4epss 0.00

    A vulnerability was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with versions Exynos 9820, Exynos 9825, Exynos 980, Exynos 990, Exynos 850 Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380 Exynos 1330, Exynos 9110, Exynos W920, Exynos…

  • CVE-2024-32504HigJun 13, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper length checking, which can result in an OOB (Out-of-Bounds) Write…

  • CVE-2024-31956HigJun 13, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.

  • CVE-2024-32502HigJun 7, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper reference count checking, which can result in a UAF…

  • CVE-2024-31959HigJun 7, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in code execution.

  • CVE-2024-32503HigJun 7, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper memory deallocation checking, which can result in a UAF…

  • CVE-2024-20845HigApr 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds write vulnerability while releasing memory in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2024-20844HigApr 2, 2024
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds write vulnerability while parsing remaining codewords in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2024-20813HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2024-20812HigFeb 6, 2024
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-42537HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

  • CVE-2023-42536HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.

  • CVE-2023-42535HigNov 7, 2023
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-30692HigOct 4, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30690HigOct 4, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30710HigSep 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30691HigAug 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.

  • CVE-2023-30680HigAug 10, 2023
    risk 0.55cvss 8.4epss 0.00

    Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.

  • CVE-2023-30664HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30658HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-30656HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.

  • CVE-2023-30655HigJul 6, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.

  • CVE-2023-21491HigMay 4, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.

  • CVE-2023-21439HigFeb 9, 2023
    risk 0.55cvss 8.5epss 0.00

    Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.

  • CVE-2022-33704HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-33703HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30756HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder.

  • CVE-2022-30754HigJul 12, 2022
    risk 0.55cvss 8.5epss 0.00

    Implicit Intent hijacking vulnerability in AppLinker prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of AppLinker.

  • CVE-2022-30713HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

  • CVE-2022-30712HigJun 7, 2022
    risk 0.55cvss 8.5epss 0.00

    Improper validation vulnerability in KfaOptions prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

Page 6 of 47