Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21476 | Hig | 0.52 | 8.0 | 0.00 | Sep 3, 2025 | Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2023-21475 | Hig | 0.52 | 8.0 | 0.00 | Sep 3, 2025 | Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2025-53078 | Hig | 0.52 | 8.0 | 0.00 | Jul 29, 2025 | Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system | ||
| CVE-2024-20816 | Hig | 0.52 | 8.0 | 0.00 | Feb 6, 2024 | Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness. | ||
| CVE-2024-20815 | Hig | 0.52 | 8.0 | 0.00 | Feb 6, 2024 | Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness. | ||
| CVE-2022-39882 | Hig | 0.52 | 8.0 | 0.00 | Nov 9, 2022 | Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2022-39852 | Hig | 0.52 | 8.0 | 0.00 | Oct 7, 2022 | A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform code execution. | ||
| CVE-2021-25372 | Med | 0.52 | 6.1 | 0.01 | KEV | Mar 26, 2021 | An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. | |
| CVE-2021-25371 | Med | 0.52 | 6.1 | 0.01 | KEV | Mar 26, 2021 | A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. | |
| CVE-2021-25370 | Med | 0.52 | 6.1 | 0.01 | KEV | Mar 26, 2021 | An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic. | |
| CVE-2021-25369 | Med | 0.52 | 6.2 | 0.01 | KEV | Mar 26, 2021 | An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. | |
| CVE-2020-8860 | Hig | 0.52 | 8.0 | 0.01 | Feb 22, 2020 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this vulnerability in that the target must… | ||
| CVE-2012-3810 | Hig | 0.52 | 7.5 | 0.05 | Jan 9, 2020 | Samsung Kies before 2.5.0.12094_27_11 has registry modification. | ||
| CVE-2012-3809 | Hig | 0.52 | 7.5 | 0.05 | Jan 9, 2020 | Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification. | ||
| CVE-2012-3808 | Hig | 0.52 | 7.5 | 0.05 | Jan 9, 2020 | Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification. | ||
| CVE-2015-0864 | Hig | 0.52 | 8.0 | 0.01 | Mar 27, 2017 | Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code. | ||
| CVE-2015-0863 | Hig | 0.52 | 8.0 | 0.01 | Mar 27, 2017 | GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code. | ||
| CVE-2026-23789 | Hig | 0.51 | 7.8 | 0.00 | Sep 14, 2026 | An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of… | ||
| CVE-2026-21089 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2026 | Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2026-21088 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2026 | Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2026-21072 | Hig | 0.51 | 7.8 | 0.00 | Aug 10, 2026 | Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2026-21071 | Hig | 0.51 | 7.8 | 0.00 | Aug 10, 2026 | Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2026-21069 | Hig | 0.51 | 7.8 | 0.00 | Aug 10, 2026 | Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2026-21068 | Hig | 0.51 | 7.8 | 0.00 | Aug 10, 2026 | Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. | ||
| CVE-2026-21066 | Hig | 0.51 | 7.8 | 0.00 | Aug 10, 2026 | Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2026-21065 | Hig | 0.51 | 7.8 | 0.00 | Aug 10, 2026 | Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2026-21031 | Hig | 0.51 | 7.8 | 0.00 | Jun 5, 2026 | Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability. | ||
| CVE-2026-21030 | Hig | 0.51 | 7.8 | 0.00 | Jun 5, 2026 | Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions. | ||
| CVE-2026-21029 | Hig | 0.51 | 7.8 | 0.00 | Jun 5, 2026 | Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations. | ||
| CVE-2026-21020 | Hig | 0.51 | 7.8 | 0.00 | May 13, 2026 | Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions. | ||
| CVE-2026-25203 | Hig | 0.51 | 7.8 | 0.00 | Apr 10, 2026 | Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 21.1091.1. | ||
| CVE-2026-20983 | Hig | 0.51 | 7.8 | 0.00 | Feb 4, 2026 | Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege. | ||
| CVE-2026-20979 | Hig | 0.51 | 7.8 | 0.00 | Feb 4, 2026 | Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege. | ||
| CVE-2026-20976 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2026 | Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script. | ||
| CVE-2026-20971 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2026 | Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code. | ||
| CVE-2026-20970 | Hig | 0.51 | 7.8 | 0.00 | Jan 9, 2026 | Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs. | ||
| CVE-2025-57836 | Hig | 0.51 | 7.8 | 0.00 | Jan 5, 2026 | An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges. | ||
| CVE-2025-21062 | Hig | 0.51 | 7.8 | 0.00 | Oct 10, 2025 | Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability. | ||
| CVE-2023-21477 | Hig | 0.51 | 7.9 | 0.00 | Sep 3, 2025 | Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data. | ||
| CVE-2025-23098 | Hig | 0.51 | 7.8 | 0.00 | Jun 3, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation. | ||
| CVE-2025-23105 | Hig | 0.51 | 7.8 | 0.00 | Jun 2, 2025 | An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation. | ||
| CVE-2024-5760 | Hig | 0.51 | 7.8 | 0.00 | Sep 11, 2024 | The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This is only applicable for products in the application released or manufactured before 2018. | ||
| CVE-2024-31960 | Hig | 0.51 | 7.8 | 0.00 | Sep 10, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to a use after free. | ||
| CVE-2024-34623 | Hig | 0.51 | 7.8 | 0.00 | Aug 7, 2024 | Out-of-bounds write in applying connected information in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege. | ||
| CVE-2024-34622 | Hig | 0.51 | 7.8 | 0.00 | Aug 7, 2024 | Out-of-bounds write in appending paragraph in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege. | ||
| CVE-2024-34595 | Hig | 0.51 | 7.8 | 0.00 | Jul 2, 2024 | Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2024-34585 | Hig | 0.51 | 7.8 | 0.00 | Jul 2, 2024 | Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2024-20891 | Hig | 0.51 | 7.8 | 0.00 | Jul 2, 2024 | Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2024-20888 | Hig | 0.51 | 7.8 | 0.00 | Jul 2, 2024 | Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-20874 | Hig | 0.51 | 7.9 | 0.00 | Jun 4, 2024 | Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities. |
- risk 0.52cvss 8.0epss 0.00
Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.
- risk 0.52cvss 8.0epss 0.00
Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.
- risk 0.52cvss 8.0epss 0.00
Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system
- risk 0.52cvss 8.0epss 0.00
Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
- risk 0.52cvss 8.0epss 0.00
Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
- risk 0.52cvss 8.0epss 0.00
Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.
- risk 0.52cvss 8.0epss 0.00
A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform code execution.
- risk 0.52cvss 6.1epss 0.01
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
- risk 0.52cvss 6.1epss 0.01
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
- risk 0.52cvss 6.1epss 0.01
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
- risk 0.52cvss 6.2epss 0.01
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
- risk 0.52cvss 8.0epss 0.01
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this vulnerability in that the target must…
- risk 0.52cvss 7.5epss 0.05
Samsung Kies before 2.5.0.12094_27_11 has registry modification.
- risk 0.52cvss 7.5epss 0.05
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.
- risk 0.52cvss 7.5epss 0.05
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.
- risk 0.52cvss 8.0epss 0.01
Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
- risk 0.52cvss 8.0epss 0.01
GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of…
- risk 0.51cvss 7.8epss 0.00
Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.51cvss 7.8epss 0.00
Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.51cvss 7.8epss 0.00
Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.51cvss 7.8epss 0.00
Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.51cvss 7.8epss 0.00
Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.00
Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.51cvss 7.8epss 0.00
Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.
- risk 0.51cvss 7.8epss 0.00
Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.
- risk 0.51cvss 7.8epss 0.00
Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.
- risk 0.51cvss 7.8epss 0.00
Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.
- risk 0.51cvss 7.8epss 0.00
Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 21.1091.1.
- risk 0.51cvss 7.8epss 0.00
Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege.
- risk 0.51cvss 7.8epss 0.00
Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege.
- risk 0.51cvss 7.8epss 0.00
Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.
- risk 0.51cvss 7.8epss 0.00
Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.
- risk 0.51cvss 7.8epss 0.00
Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges.
- risk 0.51cvss 7.8epss 0.00
Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.
- risk 0.51cvss 7.9epss 0.00
Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.
- risk 0.51cvss 7.8epss 0.00
The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This is only applicable for products in the application released or manufactured before 2018.
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to a use after free.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds write in applying connected information in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds write in appending paragraph in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.
- risk 0.51cvss 7.8epss 0.00
Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.
- risk 0.51cvss 7.8epss 0.00
Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.
- risk 0.51cvss 7.8epss 0.00
Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.
- risk 0.51cvss 7.8epss 0.00
Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
- risk 0.51cvss 7.9epss 0.00
Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities.
Page 8 of 47