Lucene search

K

Samsung Mobile Devices Security Vulnerabilities

cve
cve

CVE-2021-25485

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote...

8CVSS

7.8AI Score

0.0004EPSS

2021-10-06 06:15 PM
25
cve
cve

CVE-2021-25489

Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel...

5.5CVSS

5.6AI Score

0.001EPSS

2021-10-06 06:15 PM
265
In Wild
cve
cve

CVE-2021-25490

A keyblob downgrade attack in keymaster prior to SMR Oct-2021 Release 1 allows attacker to trigger IV reuse vulnerability with privileged...

6CVSS

6.1AI Score

0.0004EPSS

2021-10-06 06:15 PM
28
cve
cve

CVE-2021-25479

A possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code...

7.2CVSS

7.3AI Score

0.001EPSS

2021-10-06 06:15 PM
19
cve
cve

CVE-2021-25480

A lack of replay attack protection in GUTI REALLOCATION COMMAND message process in Qualcomm modem prior to SMR Oct-2021 Release 1 can lead to remote denial of service on mobile network...

7.5CVSS

7.4AI Score

0.001EPSS

2021-10-06 06:15 PM
26
cve
cve

CVE-2021-25481

An improper error handling in Exynos CP booting driver prior to SMR Oct-2021 Release 1 allows local attackers to bypass a Secure Memory Protector of Exynos CP...

6.7CVSS

6.3AI Score

0.0004EPSS

2021-10-06 06:15 PM
21
cve
cve

CVE-2021-25486

Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in...

3.3CVSS

4AI Score

0.0004EPSS

2021-10-06 06:15 PM
24
cve
cve

CVE-2021-25468

A possible guessing and confirming a byte memory vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows attackers to read arbitrary memory...

4.4CVSS

4.7AI Score

0.0004EPSS

2021-10-06 06:15 PM
17
2
cve
cve

CVE-2021-25471

A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery...

7.5CVSS

7.4AI Score

0.001EPSS

2021-10-06 06:15 PM
22
cve
cve

CVE-2021-25467

Assuming system privilege is gained, possible buffer overflow vulnerabilities in the Vision DSP kernel driver prior to SMR Oct-2021 Release 1 allows privilege escalation to Root by hijacking loaded...

6.7CVSS

6.9AI Score

0.0004EPSS

2021-10-06 06:15 PM
19
cve
cve

CVE-2021-25470

An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise...

7.9CVSS

7.6AI Score

0.0004EPSS

2021-10-06 06:15 PM
19
cve
cve

CVE-2021-25472

An improper access control vulnerability in BluetoothSettingsProvider prior to SMR Oct-2021 Release 1 allows untrusted application to overwrite some Bluetooth...

4CVSS

4.1AI Score

0.0004EPSS

2021-10-06 06:15 PM
19
cve
cve

CVE-2021-25473

Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_hide_by_meadia_full value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory...

4.4CVSS

4.7AI Score

0.0004EPSS

2021-10-06 06:15 PM
18
cve
cve

CVE-2021-25469

A possible stack-based buffer overflow vulnerability in Widevine trustlet prior to SMR Oct-2021 Release 1 allows arbitrary code...

6.7CVSS

7AI Score

0.0004EPSS

2021-10-06 06:15 PM
20
cve
cve

CVE-2021-25475

A possible heap-based buffer overflow vulnerability in DSP kernel driver prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code...

6.7CVSS

6.9AI Score

0.0004EPSS

2021-10-06 06:15 PM
17
cve
cve

CVE-2021-25474

Assuming a shell privilege is gained, an improper exception handling for multi_sim_bar_show_on_qspanel value in SystemUI prior to SMR Oct-2021 Release 1 allows an attacker to cause a permanent denial of service in user device before factory...

4.4CVSS

4.8AI Score

0.0004EPSS

2021-10-06 06:15 PM
23
cve
cve

CVE-2021-25461

An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer...

7.8CVSS

7.5AI Score

0.0004EPSS

2021-09-09 07:15 PM
26
cve
cve

CVE-2021-25462

NULL pointer dereference vulnerability in NPU driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory...

5.5CVSS

5.4AI Score

0.0004EPSS

2021-09-09 07:15 PM
20
cve
cve

CVE-2021-25453

Some improper access control in Bluetooth APIs prior to SMR Sep-2021 Release 1 allows untrusted application to get Bluetooth...

5.5CVSS

5.5AI Score

0.0004EPSS

2021-09-09 07:15 PM
21
cve
cve

CVE-2021-25455

OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi...

3.3CVSS

4.2AI Score

0.0005EPSS

2021-09-09 07:15 PM
25
cve
cve

CVE-2021-25458

NULL pointer dereference vulnerability in ION driver prior to SMR Sep-2021 Release 1 allows attackers to cause memory...

5.5CVSS

5.4AI Score

0.0004EPSS

2021-09-09 07:15 PM
21
cve
cve

CVE-2021-25460

An improper access control vulnerability in sspExit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to terminate...

5.5CVSS

5.4AI Score

0.0004EPSS

2021-09-09 07:15 PM
24
cve
cve

CVE-2021-25454

OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac...

5.5CVSS

5.6AI Score

0.0005EPSS

2021-09-09 07:15 PM
20
cve
cve

CVE-2021-25456

OOB read vulnerability in libswmfextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute memcpy at arbitrary address via forged wmf...

5.5CVSS

5.6AI Score

0.0005EPSS

2021-09-09 07:15 PM
18
cve
cve

CVE-2021-25457

An improper input validation vulnerability in DSP driver prior to SMR Sep-2021 Release 1 allows local attackers to get a limited kernel memory...

5.9CVSS

3.9AI Score

0.0004EPSS

2021-09-09 07:15 PM
25
cve
cve

CVE-2021-25459

An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep-2021 Release 1 allows attackers to start...

5.5CVSS

5.4AI Score

0.0004EPSS

2021-09-09 07:15 PM
27
cve
cve

CVE-2021-25452

An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the...

5.5CVSS

5.5AI Score

0.0004EPSS

2021-09-09 07:15 PM
23
cve
cve

CVE-2021-25451

A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI...

3.3CVSS

4.1AI Score

0.0005EPSS

2021-09-09 07:15 PM
21
cve
cve

CVE-2021-25450

Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote...

6.5CVSS

6.5AI Score

0.0005EPSS

2021-09-09 07:15 PM
21
cve
cve

CVE-2021-25449

An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers to execute arbitrary code in mediaextractor...

9.8CVSS

9.6AI Score

0.001EPSS

2021-09-09 07:15 PM
22
cve
cve

CVE-2021-25443

A use after free vulnerability in conn_gadget driver prior to SMR AUG-2021 Release 1 allows malicious action by an...

5.3CVSS

5.3AI Score

0.0004EPSS

2021-08-05 08:15 PM
19
2
cve
cve

CVE-2021-25444

An IV reuse vulnerability in keymaster prior to SMR AUG-2021 Release 1 allows decryption of custom keyblob with privileged...

5.5CVSS

5.9AI Score

0.0004EPSS

2021-08-05 08:15 PM
30
2
cve
cve

CVE-2021-25426

Improper component protection vulnerability in SmsViewerActivity of Samsung Message prior to SMR July-2021 Release 1 allows untrusted applications to access Message...

7.5CVSS

7.4AI Score

0.001EPSS

2021-07-08 02:15 PM
21
2
cve
cve

CVE-2021-25430

Improper access control vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth...

4.3CVSS

4.5AI Score

0.0005EPSS

2021-07-08 02:15 PM
21
cve
cve

CVE-2021-25427

SQL injection vulnerability in Bluetooth prior to SMR July-2021 Release 1 allows unauthorized access to paired device...

6.5CVSS

6.6AI Score

0.0005EPSS

2021-07-08 02:15 PM
19
cve
cve

CVE-2021-25429

Improper privilege management vulnerability in Bluetooth application prior to SMR July-2021 Release 1 allows untrusted application to access the Bluetooth information in Bluetooth...

4.3CVSS

4.5AI Score

0.0005EPSS

2021-07-08 02:15 PM
21
4
cve
cve

CVE-2021-25428

Improper validation check vulnerability in PackageManager prior to SMR July-2021 Release 1 allows untrusted applications to get dangerous level permission without user confirmation in limited...

7.8CVSS

7.5AI Score

0.0004EPSS

2021-07-08 02:15 PM
24
cve
cve

CVE-2021-25411

Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel...

4.4CVSS

4.5AI Score

0.0004EPSS

2021-06-11 03:15 PM
18
6
cve
cve

CVE-2021-25413

Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbitrary data with Samsung Contacts...

5.5CVSS

5.4AI Score

0.0004EPSS

2021-06-11 03:15 PM
14
cve
cve

CVE-2021-25414

Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to copy or overwrite arbitrary files with Samsung Contacts...

7.8CVSS

7.4AI Score

0.0004EPSS

2021-06-11 03:15 PM
16
2
cve
cve

CVE-2021-25409

Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring...

2.4CVSS

4.2AI Score

0.0005EPSS

2021-06-11 03:15 PM
21
4
cve
cve

CVE-2021-25415

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as...

5.5CVSS

5.3AI Score

0.0004EPSS

2021-06-11 03:15 PM
15
2
cve
cve

CVE-2021-25416

Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code...

6.5CVSS

6.3AI Score

0.0004EPSS

2021-06-11 03:15 PM
12
4
cve
cve

CVE-2021-25417

Improper authorization in SDP SDK prior to SMR JUN-2021 Release 1 allows access to internal...

7.5CVSS

7.4AI Score

0.001EPSS

2021-06-11 03:15 PM
23
2
cve
cve

CVE-2021-25410

Improper access control of a component in CallBGProvider prior to SMR JUN-2021 Release 1 allows local attackers to access arbitrary files with an escalated...

7.1CVSS

6.8AI Score

0.0004EPSS

2021-06-11 03:15 PM
32
cve
cve

CVE-2021-25412

An improper access control vulnerability in genericssoservice prior to SMR JUN-2021 Release 1 allows local attackers to execute protected activity with system privilege via untrusted...

7.8CVSS

7.6AI Score

0.0004EPSS

2021-06-11 03:15 PM
17
cve
cve

CVE-2021-25408

A possible buffer overflow vulnerability in NPU driver prior to SMR JUN-2021 Release 1 allows arbitrary memory write and code...

7.8CVSS

7.9AI Score

0.0004EPSS

2021-06-11 03:15 PM
21
cve
cve

CVE-2021-25397

An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted...

6.8CVSS

6.2AI Score

0.0004EPSS

2021-06-11 03:15 PM
30
cve
cve

CVE-2021-25395

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is...

6.4CVSS

6.5AI Score

0.002EPSS

2021-06-11 03:15 PM
255
In Wild
4
cve
cve

CVE-2021-25396

An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code...

6.7CVSS

6.8AI Score

0.0004EPSS

2021-06-11 03:15 PM
20
Total number of security vulnerabilities549