Samsung Mobile Devices vulnerabilities
375 known vulnerabilities affecting samsung_mobile/samsung_mobile_devices.
Total CVEs
375
CISA KEV
11
actively exploited
Public exploits
0
Exploited in wild
11
Severity breakdown
CRITICAL37HIGH101MEDIUM142LOW95
Vulnerabilities
Page 2 of 19
CVE-2023-21496MEDIUMCVSS 5.5≥ Android 11, 12, 13, < SMR May-2023 Release 12023-05-04
CVE-2023-21496 [MEDIUM] CWE-489 CVE-2023-21496: Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows att
Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.
cvelistv5nvd
CVE-2023-21500MEDIUMCVSS 5.5≥ Select Android 13 devices, < SMR May-2023 Release 12023-05-04
CVE-2023-21500 [MEDIUM] CWE-415 CVE-2023-21500: Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 R
Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
cvelistv5nvd
CVE-2023-21495MEDIUMCVSS 5.5≥ Android 11, 12, 13, < SMR May-2023 Release 12023-05-04
CVE-2023-21495 [MEDIUM] CWE-284 CVE-2023-21495: Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 all
Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
cvelistv5nvd
CVE-2023-21487LOWCVSS 3.3≥ Android 11, 12, 13, < SMR May-2023 Release 12023-05-04
CVE-2023-21487 [LOW] CWE-287 CVE-2023-21487: Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows
Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.
cvelistv5nvd
CVE-2023-21459CRITICALCVSS 9.8≥ Android 11, 12, 13 devices with Exynos2100 chipset, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21459 [CRITICAL] CWE-416 CVE-2023-21459: Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cau
Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.
cvelistv5nvd
CVE-2023-21455CRITICALCVSS 9.1≥ Select devices using Exynos CP chipsets, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21455 [CRITICAL] CWE-287 CVE-2023-21455: Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows inco
Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.
cvelistv5nvd
CVE-2023-21457HIGHCVSS 8.1≥ Android 11, 12, 13, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21457 [HIGH] CWE-284 CVE-2023-21457: Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers
Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.
cvelistv5nvd
CVE-2023-21460MEDIUMCVSS 4.4≥ Android 11, 12, 13, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21460 [MEDIUM] CWE-287 CVE-2023-21460: Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the
Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
cvelistv5nvd
CVE-2023-21461MEDIUMCVSS 5.5≥ Android 12, 13, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21461 [MEDIUM] CWE-285 CVE-2023-21461: Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-202
Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
cvelistv5nvd
CVE-2023-21453MEDIUMCVSS 5.5≥ Selected Android 13 devices, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21453 [MEDIUM] CWE-20 CVE-2023-21453: Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local a
Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
cvelistv5nvd
CVE-2023-21449MEDIUMCVSS 5.5≥ Select Android 11, 12 devices, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21449 [MEDIUM] CWE-200 CVE-2023-21449: Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows loc
Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.
cvelistv5nvd
CVE-2023-21456MEDIUMCVSS 5.5≥ Android 11, 12, 13, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21456 [MEDIUM] CWE-22 CVE-2023-21456: Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacke
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
cvelistv5nvd
CVE-2023-21458LOWCVSS 3.3≥ Android 11, 12, 13, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21458 [LOW] CWE-269 CVE-2023-21458: Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-20
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
cvelistv5nvd
CVE-2023-21454LOWCVSS 2.4≥ Android 13, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21454 [LOW] CWE-285 CVE-2023-21454: Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker
Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.
cvelistv5nvd
CVE-2023-21452LOWCVSS 3.3≥ Android 11, 12, 13, < SMR Mar-2023 Release 12023-03-16
CVE-2023-21452 [LOW] CWE-285 CVE-2023-21452: Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to ge
Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
cvelistv5nvd
CVE-2023-21419HIGHCVSS 7.5≥ S(12), < SMR Jan-2023 Release 12023-02-09
CVE-2023-21419 [HIGH] CWE-287 CVE-2023-21419: An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure
An improper implementation logic in Secure Folder prior to SMR Jan-2023 Release 1 allows the Secure Folder container remain unlocked under certain condition.
cvelistv5nvd
CVE-2023-21430HIGHCVSS 7.8≥ Q(10), R(11), S(12), T(13), < SMR Jan-2023 Release 12023-02-09
CVE-2023-21430 [HIGH] CWE-125 CVE-2023-21430: An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.
An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.
cvelistv5nvd
CVE-2023-21420HIGHCVSS 7.8≥ Q(10), R(11) devices with Teegris, < SMR Jan-2023 Release 12023-02-09
CVE-2023-21420 [HIGH] CWE-134 CVE-2023-21420: Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release
Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.
cvelistv5nvd
CVE-2023-21451HIGHCVSS 7.8≥ unspecified, < Android S(12)2023-02-09
CVE-2023-21451 [HIGH] CWE-20 CVE-2023-21451: A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allow
A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.
cvelistv5nvd
CVE-2023-21439HIGHCVSS 7.8≥ S(12), T(13), < SMR Feb-2023 Release 12023-02-09
CVE-2023-21439 [HIGH] CWE-20 CVE-2023-21439: Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allo
Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.
cvelistv5nvd