Samsung Notes vulnerabilities
63 known vulnerabilities affecting samsung/notes.
Total CVEs
63
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH31MEDIUM24LOW7
Vulnerabilities
Page 2 of 4
CVE-2021-25496P3HIGHCVSS 7.8fixed in 4.3.02.612021-10-06
CVE-2021-25496 [HIGH] CWE-120 CVE-2021-25496: A possible buffer overflow vulnerability in maetd_dec_slice of libSPenBase library of Samsung Notes
A possible buffer overflow vulnerability in maetd_dec_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.
nvd
CVE-2021-25498P3HIGHCVSS 7.8fixed in 4.3.02.612021-10-06
CVE-2021-25498 [HIGH] CWE-120 CVE-2021-25498: A possible buffer overflow vulnerability in maetd_eco_cb_mode of libSPenBase library of Samsung Note
A possible buffer overflow vulnerability in maetd_eco_cb_mode of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.
nvd
CVE-2021-25355P3HIGHCVSS 7.8fixed in 4.2.00.222021-03-25
CVE-2021-25355 [HIGH] CWE-285 CVE-2021-25355: Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauth
Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
nvd
CVE-2018-10501P4HIGHCVSS 7.0fixed in 2.0.02.312018-09-24
CVE-2018-10501 [HIGH] CWE-22 CVE-2018-10501: This vulnerability allows local attackers to escalate privileges on vulnerable installations of Sams
This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Notes Fixed in version 2.0.02.31. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of ZIP files. The issue results from
nvd
CVE-2025-21068P4HIGHCVSS 7.1fixed in 4.4.30.632025-10-10
CVE-2025-21068 [HIGH] CWE-125 CVE-2025-21068: Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows l
Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
nvd
CVE-2025-21066P4HIGHCVSS 7.1fixed in 4.4.30.632025-10-10
CVE-2025-21066 [HIGH] CWE-125 CVE-2025-21066: Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attac
Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
nvd
CVE-2025-21069P4HIGHCVSS 7.1fixed in 4.4.30.632025-10-10
CVE-2025-21069 [HIGH] CWE-125 CVE-2025-21069: Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows l
Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
nvd
CVE-2025-21067P4HIGHCVSS 7.1fixed in 4.4.30.632025-10-10
CVE-2025-21067 [HIGH] CWE-125 CVE-2025-21067: Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 all
Out-of-bounds read in the allocation of image buffer in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
nvd
CVE-2024-20868P4HIGHCVSS 7.1fixed in 4.4.152024-05-07
CVE-2024-20868 [HIGH] CVE-2024-20868: Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete
Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege under certain conditions.
nvd
CVE-2021-25367P4MEDIUMCVSS 5.4fixed in 4.2.00.222021-03-25
CVE-2021-25367 [MEDIUM] CWE-22 CVE-2021-25367: Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access
Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.
nvd
CVE-2024-34658P4HIGHCVSS 7.1fixed in 4.4.21.622024-09-04
CVE-2024-34658 [HIGH] CWE-125 CVE-2024-34658: Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.
Out-of-bounds read in Samsung Notes allows local attackers to bypass ASLR.
nvd
CVE-2021-25493P4HIGHCVSS 7.1≤ 4.3.02.612021-10-06
CVE-2021-25493 [HIGH] CWE-125 CVE-2021-25493: Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note
Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read
nvd
CVE-2021-25492P4HIGHCVSS 7.1≤ 4.3.02.612021-10-06
CVE-2021-25492 [HIGH] CWE-787 CVE-2021-25492: Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note
Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.
nvd
CVE-2022-36831P4MEDIUMCVSS 5.5fixed in 4.3.14.392022-08-05
CVE-2022-36831 [MEDIUM] CWE-22 CVE-2022-36831: Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows atta
Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.
nvd
CVE-2025-21070P4MEDIUMCVSS 5.5fixed in 4.4.30.632025-10-10
CVE-2025-21070 [MEDIUM] CWE-787 CVE-2025-21070: Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local atta
Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.
nvd
CVE-2024-34621P4MEDIUMCVSS 5.5fixed in 4.4.21.622024-08-07
CVE-2024-34621 [MEDIUM] CWE-125 CVE-2024-34621: Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows l
Out-of-bounds read in applying binary with data in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
nvd
CVE-2024-34628P4MEDIUMCVSS 5.5fixed in 4.4.21.622024-08-07
CVE-2024-34628 [MEDIUM] CWE-125 CVE-2024-34628: Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows l
Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.
nvd
CVE-2025-20913P4MEDIUMCVSS 5.5fixed in 4.4.26.712025-03-06
CVE-2025-20913 [MEDIUM] CWE-125 CVE-2025-20913: Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71
Out-of-bounds read in applying binary of drawing content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
nvd
CVE-2025-20932P4MEDIUMCVSS 5.5fixed in 4.4.26.712025-03-06
CVE-2025-20932 [MEDIUM] CWE-125 CVE-2025-20932: Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows lo
Out-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memory.
nvd
CVE-2025-20950P4MEDIUMCVSS 5.5fixed in 4.4.26.452025-04-08
CVE-2025-20950 [MEDIUM] CVE-2025-20950: Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows
Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.
nvd