Samsung Mobile Devices vulnerabilities
375 known vulnerabilities affecting samsung_mobile/samsung_mobile_devices.
Total CVEs
375
CISA KEV
11
actively exploited
Public exploits
0
Exploited in wild
11
Severity breakdown
CRITICAL37HIGH101MEDIUM142LOW95
Vulnerabilities
Page 14 of 19
CVE-2022-22266LOWCVSS 3.3≥ P(9.0), Q(10.0), R(11.0), < SMR Jan-2022 Release 12022-01-10
CVE-2022-22266 [LOW] CWE-269 CVE-2022-22266: (Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity applicati
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity application prior to SMR Jan-2022 Release 1 allows untrusted applications to get WiFi information without proper permission.
cvelistv5nvd
CVE-2022-22267LOWCVSS 3.3≥ P(9.0), Q(10.0), R(11.0), S(12.0), < SMR Jan-2022 Release 12022-01-10
CVE-2022-22267 [LOW] CWE-285 CVE-2022-22267: Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 all
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1 allows attackers to get running application information.
cvelistv5nvd
CVE-2022-22269LOWCVSS 3.3≥ P(9.0), Q(10.0), R(11.0), < SMR Jan-2022 Release 12022-01-10
CVE-2022-22269 [LOW] CWE-285 CVE-2022-22269: Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allo
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1 allows untrusted applications to get a local Bluetooth MAC address.
cvelistv5nvd
CVE-2021-25511HIGHCVSS 7.8≥ P(9.0), Q(10.0), R(11.0), < SMR Dec-2021 Release 12021-12-08
CVE-2021-25511 [HIGH] CWE-20 CVE-2021-25511: An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attack
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.
cvelistv5nvd
CVE-2021-25517HIGHCVSS 7.8≥ Q(10.0), R(11.0) devices with selected Exynos chipsets, < SMR Dec-2021 Release 12021-12-08
CVE-2021-25517 [HIGH] CWE-20 CVE-2021-25517: An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers
An improper input validation vulnerability in LDFW prior to SMR Dec-2021 Release 1 allows attackers to perform arbitrary code execution.
cvelistv5nvd
CVE-2021-25512HIGHCVSS 7.8≥ P(9.0), Q(10.0), R(11.0), < SMR Dec-2021 Release 12021-12-08
CVE-2021-25512 [HIGH] CWE-20 CVE-2021-25512: An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers t
An improper validation vulnerability in telephony prior to SMR Dec-2021 Release 1 allows attackers to launch certain activities.
cvelistv5nvd
CVE-2021-25516HIGHCVSS 7.5≥ P(9.0), Q(10.0), R(11.0) devices with selected Exynos chipsets, < SMR Dec-2021 Release 12021-12-08
CVE-2021-25516 [HIGH] CWE-703 CVE-2021-25516: An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Rel
An improper check or handling of exceptional conditions in Exynos baseband prior to SMR Dec-2021 Release 1 allows attackers to track locations.
cvelistv5nvd
CVE-2021-25510HIGHCVSS 7.8≥ P(9.0), Q(10.0), R(11.0), < SMR Dec-2021 Release 12021-12-08
CVE-2021-25510 [HIGH] CWE-20 CVE-2021-25510: An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows local arbitrary code execution.
cvelistv5nvd
CVE-2021-25514MEDIUMCVSS 6.5≥ Q(10.0), R(11.0), < SMR Dec-2021 Release 12021-12-08
CVE-2021-25514 [MEDIUM] CVE-2021-25514: An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to
An improper intent redirection handling in Tags prior to SMR Dec-2021 Release 1 allows attackers to access sensitive information.
cvelistv5nvd
CVE-2021-25518MEDIUMCVSS 6.7≥ P(9.0), Q(10.0), R(11.0) devices with selected Exynos chipsets, < SMR Dec-2021 Release 12021-12-08
CVE-2021-25518 [MEDIUM] CWE-119 CVE-2021-25518: An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arb
An improper boundary check in secure_log of LDFW and BL31 prior to SMR Dec-2021 Release 1 allows arbitrary memory write and code execution.
cvelistv5nvd
CVE-2021-25513LOWCVSS 2.4≥ Select R(11.0) devices, < SMR Dec-2021 Release 12021-12-08
CVE-2021-25513 [LOW] CWE-269 CVE-2021-25513: An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Releas
An improper privilege management vulnerability in Apps Edge application prior to SMR Dec-2021 Release 1 allows unauthorized access to some device data on the lockscreen.
cvelistv5nvd
CVE-2021-25515LOWCVSS 3.3≥ P(9.0), Q(10.0), R(11.0), < SMR Dec-2021 Release 12021-12-08
CVE-2021-25515 [LOW] CWE-269 CVE-2021-25515: An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows atta
An improper usage of implicit intent in SemRewardManager prior to SMR Dec-2021 Release 1 allows attackers to access BSSID.
cvelistv5nvd
CVE-2021-25519LOWCVSS 3.3≥ P(9.0), Q(10.0), R(11.0), < SMR Dec-2021 Release 12021-12-08
CVE-2021-25519 [LOW] CWE-200 CVE-2021-25519: An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attack
An improper access control vulnerability in CPLC prior to SMR Dec-2021 Release 1 allows local attackers to access CPLC information without permission.
cvelistv5nvd
CVE-2021-25502MEDIUMCVSS 5.5≥ O(8.1), P(9.0), Q(10.0), R(11.0), < SMR Nov-2021 Release 12021-11-05
CVE-2021-25502 [MEDIUM] CWE-269 CVE-2021-25502: A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-20
A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows attackers to read ESN value without priviledge.
cvelistv5nvd
CVE-2021-25503MEDIUMCVSS 6.7≥ Select O(8.1), P(9.0), Q(10.0), R(11.0) devices with Exynos chipsets, < SMR Nov-2021 Release 12021-11-05
CVE-2021-25503 [MEDIUM] CWE-20 CVE-2021-25503: Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to
Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execution.
cvelistv5nvd
CVE-2021-25500MEDIUMCVSS 4.4≥ Select Q(10.0), R(11.0) devices with Exynos 980, 9820, 9830, 2100 chipset, < SMR Nov-2021 Release 12021-11-05
CVE-2021-25500 [MEDIUM] CWE-20 CVE-2021-25500: A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrit
A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE compromise.
cvelistv5nvd
CVE-2021-25501LOWCVSS 3.3≥ Q(10.0), R(11.0), < SMR Nov-2021 Release 12021-11-05
CVE-2021-25501 [LOW] CWE-284 CVE-2021-25501: An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR N
An improper access control vulnerability in SCloudBnRReceiver in SecTelephonyProvider prior to SMR Nov-2021 Release 1 allows untrusted application to call some protected providers.
cvelistv5nvd
CVE-2021-25478HIGHCVSS 7.2≥ O(8.1), P(9.0), Q(10.0), R(11.0), < SMR Oct-2021 Release 12021-10-06
CVE-2021-25478 [HIGH] CWE-121 CVE-2021-25478: A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Rele
A possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and code execution.
cvelistv5nvd
CVE-2021-25470HIGHCVSS 7.9≥ Select P(9.0), Q(10.0), R(11.0) devices with Exynos and Mediatek chipsets, < SMR Oct-2021 Release 12021-10-06
CVE-2021-25470 [HIGH] CWE-94 CVE-2021-25470: An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.
cvelistv5nvd
CVE-2021-25471HIGHCVSS 7.5≥ O(8.1), P(9.0), Q(10.0) devices with Exynos CP chipsets, < SMR Oct-2021 Release 12021-10-06
CVE-2021-25471 [HIGH] CWE-20 CVE-2021-25471: A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1
A lack of replay attack protection in Security Mode Command process prior to SMR Oct-2021 Release 1 can lead to denial of service on mobile network connection and battery depletion.
cvelistv5nvd