Samsung Mobile Devices vulnerabilities

375 known vulnerabilities affecting samsung_mobile/samsung_mobile_devices.

Total CVEs
375
CISA KEV
11
actively exploited
Public exploits
0
Exploited in wild
11
Severity breakdown
CRITICAL37HIGH101MEDIUM142LOW95

Vulnerabilities

Page 11 of 19
CVE-2022-26095CRITICALCVSS 9.8≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-26095 [CRITICAL] CWE-476 CVE-2022-26095: Null pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr- Null pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
cvelistv5nvd
CVE-2022-26094CRITICALCVSS 9.8≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-26094 [CRITICAL] CWE-476 CVE-2022-26094: Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr- Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
cvelistv5nvd
CVE-2022-27570CRITICALCVSS 9.8≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27570 [CRITICAL] CWE-122 CVE-2022-27570: Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
cvelistv5nvd
CVE-2022-26097CRITICALCVSS 9.8≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-26097 [CRITICAL] CWE-476 CVE-2022-26097: Null pointer dereference vulnerability in parser_unknown_property function in libsimba library prior Null pointer dereference vulnerability in parser_unknown_property function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
cvelistv5nvd
CVE-2022-27571CRITICALCVSS 9.8≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27571 [CRITICAL] CWE-122 CVE-2022-27571: Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
cvelistv5nvd
CVE-2022-26099CRITICALCVSS 9.1≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-26099 [CRITICAL] CWE-476 CVE-2022-26099: Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr- Null pointer dereference vulnerability in parser_infe function of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds read by remote attackers.
cvelistv5nvd
CVE-2022-27825HIGHCVSS 7.1≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27825 [HIGH] CWE-125 CVE-2022-27825: Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Ap Improper size check in sapefd_parse_meta_HEADER function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file.
cvelistv5nvd
CVE-2022-27573HIGHCVSS 7.2≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27573 [HIGH] CWE-20 CVE-2022-27573: Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsi Improper input validation vulnerability in parser_infe and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attackers.
cvelistv5nvd
CVE-2022-27830HIGHCVSS 7.8≥ S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27830 [HIGH] CWE-20 CVE-2022-27830: Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
cvelistv5nvd
CVE-2022-27826HIGHCVSS 7.8≥ O(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27826 [HIGH] CWE-20 CVE-2022-27826: Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows att Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
cvelistv5nvd
CVE-2022-27835HIGHCVSS 7.8≥ S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27835 [HIGH] CWE-20 CVE-2022-27835: Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory writ Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.
cvelistv5nvd
CVE-2022-27824HIGHCVSS 7.1≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27824 [HIGH] CWE-125 CVE-2022-27824: Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior t Improper size check of in sapefd_parse_meta_DESCRIPTION function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of bounds read via a crafted media file
cvelistv5nvd
CVE-2022-27574HIGHCVSS 7.2≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27574 [HIGH] CWE-20 CVE-2022-27574: Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsi Improper input validation vulnerability in parser_iloc and sheifd_find_itemIndexin fuctions of libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by privileged attacker.
cvelistv5nvd
CVE-2022-27828HIGHCVSS 7.8≥ O(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27828 [HIGH] CWE-20 CVE-2022-27828: Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attack Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
cvelistv5nvd
CVE-2022-27833HIGHCVSS 7.8≥ O(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27833 [HIGH] CWE-20 CVE-2022-27833: Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write b Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.
cvelistv5nvd
CVE-2022-26092HIGHCVSS 7.8≥ Q(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-26092 [HIGH] CWE-122 CVE-2022-26092: Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.
cvelistv5nvd
CVE-2022-27829HIGHCVSS 7.8≥ S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27829 [HIGH] CWE-20 CVE-2022-27829: Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
cvelistv5nvd
CVE-2022-27827HIGHCVSS 7.8≥ O(10), R(11), S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27827 [HIGH] CWE-20 CVE-2022-27827: Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows at Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
cvelistv5nvd
CVE-2022-27834HIGHCVSS 7.0≥ Q(10), R(11), S(12) devices with Exynos 2100, 9830, 980 chipsets, < SMR Apr-2022 Release 12022-04-11
CVE-2022-27834 [HIGH] CWE-367 CVE-2022-27834: Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-202 Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions.
cvelistv5nvd
CVE-2022-27836HIGHCVSS 7.8≥ S(12), < SMR Apr-2022 Release 12022-04-11
CVE-2022-27836 [HIGH] CWE-284 CVE-2022-27836: Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Serv Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary files access.
cvelistv5nvd
Samsung Mobile Devices vulnerabilities | cvebase