VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2023-21476HigSep 3, 2025
    risk 0.52cvss 8.0epss 0.00

    Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2023-21475HigSep 3, 2025
    risk 0.52cvss 8.0epss 0.00

    Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2025-53078HigJul 29, 2025
    risk 0.52cvss 8.0epss 0.00

    Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via write file to system

  • CVE-2024-20816HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.00

    Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

  • CVE-2024-20815HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.00

    Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.

  • CVE-2022-39882HigNov 9, 2022
    risk 0.52cvss 8.0epss 0.00

    Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.

  • CVE-2022-39852HigOct 7, 2022
    risk 0.52cvss 8.0epss 0.00

    A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform code execution.

  • CVE-2021-25372MedKEVMar 26, 2021
    risk 0.52cvss 6.1epss 0.01

    An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

  • CVE-2021-25371MedKEVMar 26, 2021
    risk 0.52cvss 6.1epss 0.01

    A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

  • CVE-2021-25370MedKEVMar 26, 2021
    risk 0.52cvss 6.1epss 0.01

    An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.

  • CVE-2021-25369MedKEVMar 26, 2021
    risk 0.52cvss 6.2epss 0.01

    An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.

  • CVE-2020-8860HigFeb 22, 2020
    risk 0.52cvss 8.0epss 0.01

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung Galaxy S10 Firmware G973FXXS3ASJA, O(8.x), P(9.0), Q(10.0) devices with Exynos chipsets. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2012-3810HigJan 9, 2020
    risk 0.52cvss 7.5epss 0.05

    Samsung Kies before 2.5.0.12094_27_11 has registry modification.

  • CVE-2012-3809HigJan 9, 2020
    risk 0.52cvss 7.5epss 0.05

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.

  • CVE-2012-3808HigJan 9, 2020
    risk 0.52cvss 7.5epss 0.05

    Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.

  • CVE-2015-0864HigMar 27, 2017
    risk 0.52cvss 8.0epss 0.01

    Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.

  • CVE-2015-0863HigMar 27, 2017
    risk 0.52cvss 8.0epss 0.01

    GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.

  • CVE-2026-23789HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driver (due to improper cleanup of…

  • CVE-2026-21089HigSep 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2026-21088HigSep 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2026-21072HigAug 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2026-21071HigAug 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2026-21069HigAug 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2026-21068HigAug 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

  • CVE-2026-21066HigAug 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2026-21065HigAug 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2026-21031HigJun 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

  • CVE-2026-21030HigJun 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.

  • CVE-2026-21029HigJun 5, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.

  • CVE-2026-21020HigMay 13, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.

  • CVE-2026-25203HigApr 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability This issue affects MagicINFO 9 Server: less than 21.1091.1.

  • CVE-2026-20983HigFeb 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege.

  • CVE-2026-20979HigFeb 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege.

  • CVE-2026-20976HigJan 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script.

  • CVE-2026-20971HigJan 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.

  • CVE-2026-20970HigJan 9, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs.

  • CVE-2025-57836HigJan 5, 2026
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Samsung Magician 6.3.0 through 8.3.2 on Windows. The installer creates a temporary folder with weak permissions during installation, allowing a non-admin user to perform DLL hijacking and escalate privileges.

  • CVE-2025-21062HigOct 10, 2025
    risk 0.51cvss 7.8epss 0.00

    Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring application. User interaction is required for triggering this vulnerability.

  • CVE-2023-21477HigSep 3, 2025
    risk 0.51cvss 7.9epss 0.00

    Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

  • CVE-2025-23098HigJun 3, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, 990, 1080, 2100, 1280, 2200, 1380. A Use-After-Free in the mobile processor leads to privilege escalation.

  • CVE-2025-23105HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 2200, 1480, and 2400. A Use-After-Free in the mobile processor leads to privilege escalation.

  • CVE-2024-5760HigSep 11, 2024
    risk 0.51cvss 7.8epss 0.00

    The Samsung Universal Print Driver for Windows is potentially vulnerable to escalation of privilege allowing the creation of a reverse shell in the tool. This is only applicable for products in the application released or manufactured before 2018.

  • CVE-2024-31960HigSep 10, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to a use after free.

  • CVE-2024-34623HigAug 7, 2024
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write in applying connected information in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.

  • CVE-2024-34622HigAug 7, 2024
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write in appending paragraph in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially execute arbitrary code with Samsung Notes privilege.

  • CVE-2024-34595HigJul 2, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

  • CVE-2024-34585HigJul 2, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

  • CVE-2024-20891HigJul 2, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

  • CVE-2024-20888HigJul 2, 2024
    risk 0.51cvss 7.8epss 0.00

    Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.

  • CVE-2024-20874HigJun 4, 2024
    risk 0.51cvss 7.9epss 0.00

    Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities.

Page 8 of 47