VYPR

Vendor CVEs

Samsung Mobile

All CVEs

2,312 total · sorted by risk
  • CVE-2023-30733HigOct 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Stack-based Buffer Overflow in vulnerability HDCP trustlet prior to SMR Oct-2023 Release 1 allows local privileged attackers to perform code execution.

  • CVE-2023-30709HigSep 6, 2023
    risk 0.51cvss 7.9epss 0.00

    Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.

  • CVE-2023-30679HigAug 10, 2023
    risk 0.51cvss 7.8epss 0.00

    Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2023-30649HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap out of bound write vulnerability in RmtUimNeedApdu of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

  • CVE-2023-30647HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

  • CVE-2023-30646HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap out of bound write vulnerability in BroadcastSmsConfig of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

  • CVE-2023-30645HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap out of bound write vulnerability in IpcRxIncomingCBMsg of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

  • CVE-2023-30644HigJul 6, 2023
    risk 0.51cvss 7.8epss 0.00

    Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.

  • CVE-2023-24033HigMar 13, 2023
    risk 0.51cvss 7.5epss 0.33

    The Samsung Exynos Modem 5123, Exynos Modem 5300, Exynos 980, Exynos 1080, and Exynos Auto T512 baseband modem chipsets do not properly check format types specified by the Session Description Protocol (SDP) module, which can lead to a denial of service.

  • CVE-2023-21433HigFeb 9, 2023
    risk 0.51cvss 7.8epss 0.04

    Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.

  • CVE-2022-35858HigAug 4, 2022
    risk 0.51cvss 7.8epss 0.00

    The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of service, and information disclosure by invoking the function TEE_PopulateTransientObject with a large number in the…

  • CVE-2022-33710HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.

  • CVE-2022-33709HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.

  • CVE-2022-33708HigJul 12, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.

  • CVE-2022-24931HigMar 10, 2022
    risk 0.51cvss 7.9epss 0.00

    Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbitrary activity without a proper permission

  • CVE-2021-25502HigNov 5, 2021
    risk 0.51cvss 7.9epss 0.00

    A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.

  • CVE-2021-25470HigOct 6, 2021
    risk 0.51cvss 7.9epss 0.00

    An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.

  • CVE-2021-39373HigSep 1, 2021
    risk 0.51cvss 7.8epss 0.00

    Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk management. WideCharToMultiByte, WideCharStr, and MultiByteStr can contribute to password exposure.

  • CVE-2021-25441HigJul 8, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper input validation vulnerability in AR Emoji Editor prior to version 4.4.03.5 in Android Q(10.0) and above allows untrusted applications to access arbitrary files with an escalated privilege.

  • CVE-2021-25440HigJul 8, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper access control vulnerability in FactoryCameraFB prior to version 3.4.74 allows untrusted applications to access arbitrary files with an escalated privilege.

  • CVE-2021-25438HigJul 8, 2021
    risk 0.51cvss 7.8epss 0.02

    Improper access control vulnerability in Samsung Members prior to versions 2.4.85.11 in Android O(8.1) and below, and 3.9.10.11 in Android P(9.0) and above allows untrusted applications to cause local file inclusion in webview.

  • CVE-2021-25428HigJul 8, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permission without user confirmation in limited circumstances.

  • CVE-2021-25418HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper component protection vulnerability in Samsung Internet prior to version 14.0.1.62 allows untrusted applications to execute arbitrary activity in specific condition.

  • CVE-2021-25414HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary files with Samsung Contacts privilege.

  • CVE-2021-25412HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted applications.

  • CVE-2021-25408HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code execution.

  • CVE-2021-25407HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    A possible out of bounds write vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write.

  • CVE-2021-25401HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.

  • CVE-2021-25400HigJun 11, 2021
    risk 0.51cvss 7.8epss 0.00

    Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.

  • CVE-2021-3438HigMay 20, 2021
    risk 0.51cvss 7.8epss 0.03

    A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege.

  • CVE-2021-25361HigApr 9, 2021
    risk 0.51cvss 7.9epss 0.00

    An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.

  • CVE-2020-28343HigNov 8, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 980, 9820, and 9830 chipsets) software. The NPU driver allows attackers to execute arbitrary code because of unintended write and read operations on memory. The Samsung ID is SVE-2020-18610…

  • CVE-2020-28342HigNov 8, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (China / India) software. The S Secure application allows attackers to bypass authentication for a locked Gallery application via the Reminder application. The Samsung ID is SVE-2020-18689 (November 2020).

  • CVE-2020-28341HigNov 8, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with Q(10.0) (Exynos990 chipsets) software. The S3K250AF Secure Element CC EAL 5+ chip allows attackers to execute arbitrary code and obtain sensitive information via a buffer overflow. The Samsung ID is SVE-2020-18632 (November…

  • CVE-2020-12751HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.X), P(9.0), and Q(10.0) software. The Quram image codec library allows attackers to overwrite memory and execute arbitrary code via crafted JPEG data that is mishandled during decoding. The Samsung ID is SVE-2020-16943…

  • CVE-2020-12749HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The S.LSI Wi-Fi drivers have a buffer overflow. The Samsung ID is SVE-2020-16906 (May 2020).

  • CVE-2016-11052HigApr 7, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so in Qjpeg in Qt 5.5 allows memory corruption via a malformed JPEG file. The Samsung ID is SVE-2015-5110 (January 2016).

  • CVE-2016-11047HigApr 7, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with JBP(4.2) and KK(4.4) (Marvell chipsets) software. The ACIPC-MSOCKET driver allows local privilege escalation via a stack-based buffer overflow. The Samsung ID is SVE-2016-5393 (April 2016).

  • CVE-2016-11044HigApr 7, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signature can be bypassed during installation. The Samsung ID is SVE-2016-5923 (June 2016).

  • CVE-2019-20591HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Gear VR Service Content Provider. The Samsung ID is SVE-2019-14058 (July 2019).

  • CVE-2019-20574HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Wi-Fi history Content Provider. The Samsung ID is SVE-2019-14061 (August 2019).

  • CVE-2020-10852HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is a stack overflow in display driver. The Samsung ID is SVE-2019-15877 (January 2020).

  • CVE-2020-10851HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is a stack overflow in the kperfmon driver. The Samsung ID is SVE-2019-15876 (January 2020).

  • CVE-2020-10841HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) software. There is an arbitrary kfree in the vipx and vertex drivers. The Samsung ID is SVE-2019-16294 (February 2020).

  • CVE-2020-10838HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. PROCA allows a use-after-free and arbitrary code execution. The Samsung ID is SVE-2019-16132 (February 2020).

  • CVE-2020-10832HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. Kernel Wi-Fi drivers allow out-of-bounds Read or Write operations (e.g., a buffer overflow). The Samsung IDs are SVE-2019-16125, SVE-2019-16134, SVE-2019-16158, SVE-2019-16159,…

  • CVE-2020-10829HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.0), P(9.0), and Q(10.0) (Broadcom chipsets) software. A kernel driver heap overflow leads to arbitrary code execution. The Samsung ID is SVE-2019-15880 (March 2020).

  • CVE-2019-20542HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (Exynos chipsets) software. There is a stack overflow in the kernel driver. The Samsung ID is SVE-2019-15034 (November 2019).

  • CVE-2019-20541HigMar 24, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi kernel drivers have a stack overflow. The Samsung IDs are SVE-2019-14965, SVE-2019-14966, SVE-2019-14968, SVE-2019-14969, SVE-2019-14970, SVE-2019-14980, SVE-2019-14981,…

  • CVE-2019-19273HigFeb 4, 2020
    risk 0.51cvss 7.8epss 0.00

    On Samsung mobile devices with O(8.0) and P(9.0) software and an Exynos 8895 chipset, RKP (aka the Samsung Hypervisor EL2 implementation) allows arbitrary memory write operations. The Samsung ID is SVE-2019-16265.

Page 9 of 47