cbcvebase.

Samsung Mobile Devices vulnerabilities

374 known vulnerabilities affecting samsung_mobile/samsung_mobile_devices.

Total CVEs
374
CISA KEV
11
actively exploited
Public exploits
0
Exploited in wild
11
Severity breakdown
CRITICAL37HIGH100MEDIUM142LOW95

Vulnerabilities

Page 15 of 19
CVE-2021-25455P4LOWCVSS 3.3≥ O(8.1), P(9.0), Q(10.0), R(11.0), < SMR Sep-2021 Release 12021-09-09
CVE-2021-25455 [LOW] CWE-125 CVE-2021-25455: OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attacke OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.
nvd
CVE-2022-33690P4LOWCVSS 3.3≥ S(12), < SMR Jul-2022 Release 12022-07-12
CVE-2022-33690 [LOW] CWE-20 CVE-2022-33690: Improper input validation in Contacts Storage prior to SMR Jul-2022 Release 1 allows attacker to acc Improper input validation in Contacts Storage prior to SMR Jul-2022 Release 1 allows attacker to access arbitrary file.
nvd
CVE-2022-24929P4LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Mar-2022 Release 12022-03-10
CVE-2022-24929 [LOW] CWE-926 CVE-2022-24929: Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list o Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.
nvd
CVE-2023-21429P4LOWCVSS 3.3≥ Q(10), R(11), S(12), T(13), < SMR Jan-2023 Release 12023-02-09
CVE-2023-21429 [LOW] CWE-285 CVE-2023-21429: Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access S Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
nvd
CVE-2023-21424P4LOWCVSS 3.3≥ R(11), S(12), T(13), < SMR Jan-2023 Release 12023-02-09
CVE-2023-21424 [LOW] CWE-285 CVE-2023-21424: Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prio Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.
nvd
CVE-2022-25833P4LOWCVSS 3.3≥ Q(10), R(11), < SMR Apr-2022 Release 12022-04-11
CVE-2022-25833 [LOW] CWE-287 CVE-2022-25833: Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI w Improper authentication in ImsService prior to SMR Apr-2022 Release 1 allows attackers to get IMSI without READ_PRIVILEGED_PHONE_STATE permission.
nvd
CVE-2021-25484P4LOWCVSS 3.3≥ O(8.1 go), Q(10.0 go), R(11.0 go), < SMR Oct-2021 Release 12021-10-06
CVE-2021-25484 [LOW] CWE-287 CVE-2021-25484: Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.
nvd
CVE-2022-25817P4LOWCVSS 3.3≥ Q(10), R(11), < SMR Mar-2022 Release 12022-03-10
CVE-2022-25817 [LOW] CWE-287 CVE-2022-25817: Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate p Improper authentication in One UI Home prior to SMR Mar-2022 Release 1 allows attacker to generate pinned-shortcut without user consent.
nvd
CVE-2022-33726P4LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Aug-2022 Release 12022-08-05
CVE-2022-33726 [LOW] CWE-561 CVE-2022-33726: Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attack Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows attacker to launch activity.
nvd
CVE-2021-25336P4LOWCVSS 3.3≥ P(9.0), Q(10.0), < SMR Mar-2021 Release 12021-03-04
CVE-2021-25336 [LOW] CWE-269 CVE-2021-25336: Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-202 Improper access control in NotificationManagerService in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to acquire notification access via sending a crafted malicious intent.
nvd
CVE-2021-25451P4LOWCVSS 3.3≥ P(9.0), Q(10.0), R(11.0), < SMR Sep-2021 Release 12021-09-09
CVE-2021-25451 [LOW] CWE-287 CVE-2021-25451: A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows atta A PendingIntent hijacking in NetworkPolicyManagerService prior to SMR Sep-2021 Release 1 allows attackers to get IMSI data.
nvd
CVE-2023-21428P4LOWCVSS 3.3≥ R(11), S(12), T(13), < SMR Jan-2023 Release 12023-02-09
CVE-2023-21428 [LOW] CWE-20 CVE-2023-21428: Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attack Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.
nvd
CVE-2023-21458P4LOWCVSS 3.3≥ Android 11, 12, 13, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21458 [LOW] CWE-269 CVE-2023-21458: Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-20 Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
nvd
CVE-2023-21452P4LOWCVSS 3.3≥ Android 11, 12, 13, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21452 [LOW] CWE-285 CVE-2023-21452: Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to ge Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
nvd
CVE-2023-21436P4LOWCVSS 3.3≥ Q(10), R(11), S(12), T(13), < SMR Feb-2023 Release 12023-02-09
CVE-2023-21436 [LOW] CWE-285 CVE-2023-21436: Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
nvd
CVE-2022-39898P4LOWCVSS 3.3≥ Q(10), R(11), S(12), T(13), < SMR Dec-2022 Release 12022-12-08
CVE-2022-39898 [LOW] CWE-284 CVE-2022-39898: Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attack Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.
nvd
CVE-2022-39896P4LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Dec-2022 Release 12022-12-08
CVE-2022-39896 [LOW] CWE-284 CVE-2022-39896: Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
nvd
CVE-2022-39849P4LOWCVSS 3.3≥ S(12), < SMR Oct-2022 Release 12022-10-07
CVE-2022-39849 [LOW] CWE-284 CVE-2022-39849: Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows una Improper access control in knox_vpn_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
nvd
CVE-2022-39850P4LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Oct-2022 Release 12022-10-07
CVE-2022-39850 [LOW] CWE-284 CVE-2022-39850: Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allow Improper access control in mum_container_policy service prior to SMR Oct-2022 Release 1 allows allows unauthorized read of configuration data.
nvd
CVE-2022-39894P4LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Dec-2022 Release 12022-12-08
CVE-2022-39894 [LOW] CWE-284 CVE-2022-39894: Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-20 Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
nvd
Samsung Mobile Devices vulnerabilities | cvebase