Samsung Mobile Devices vulnerabilities
375 known vulnerabilities affecting samsung_mobile/samsung_mobile_devices.
Total CVEs
375
CISA KEV
11
actively exploited
Public exploits
0
Exploited in wild
11
Severity breakdown
CRITICAL37HIGH101MEDIUM142LOW95
Vulnerabilities
Page 4 of 19
CVE-2022-39899MEDIUMCVSS 4.3≥ Select Q(10), R(11), S(12), T(13) devices, < SMR Dec-2022 Release 12022-12-08
CVE-2022-39899 [MEDIUM] CWE-287 CVE-2022-39899: Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release
Improper authentication vulnerability in Samsung WindowManagerService prior to SMR Dec-2022 Release 1 allows attacker to send the input event using S Pen gesture.
cvelistv5nvd
CVE-2022-39901MEDIUMCVSS 6.5≥ Exynos baseband , < SMR Dec-2022 Release 12022-12-08
CVE-2022-39901 [MEDIUM] CWE-287 CVE-2022-39901: Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to
Improper authentication in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker to disable the network traffic encryption between UE and gNodeB.
cvelistv5nvd
CVE-2022-39904LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Dec-2022 Release 12022-12-08
CVE-2022-39904 [LOW] CWE-200 CVE-2022-39904: Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1
Exposure of Sensitive Information vulnerability in Samsung Settings prior to SMR Dec-2022 Release 1 allows local attackers to access the Network Access Identifier via log.
cvelistv5nvd
CVE-2022-39898LOWCVSS 3.3≥ Q(10), R(11), S(12), T(13), < SMR Dec-2022 Release 12022-12-08
CVE-2022-39898 [LOW] CWE-284 CVE-2022-39898: Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attack
Improper access control vulnerability in IIccPhoneBook prior to SMR Dec-2022 Release 1 allows attackers to access some information of usim.
cvelistv5nvd
CVE-2022-39906LOWCVSS 3.3≥ Q(10), R(11), S(12), T(13), < SMR Dec-2022 Release 12022-12-08
CVE-2022-39906 [LOW] CWE-284 CVE-2022-39906: Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows
Improper access control vulnerability in SecTelephonyProvider prior to SMR Dec-2022 Release 1 allows attackers to access message information.
cvelistv5nvd
CVE-2022-39914LOWCVSS 3.3≥ unspecified, < Android T(13)2022-12-08
CVE-2022-39914 [LOW] CWE-200 CVE-2022-39914: Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManager
Exposure of Sensitive Information from an Unauthorized Actor vulnerability in Samsung DisplayManagerService prior to Android T(13) allows local attacker to access connected DLNA device information.
cvelistv5nvd
CVE-2022-39903LOWCVSS 3.3≥ Select Q(10), R(11), S(12), T(13) devices supporting RCS, < SMR Dec-2022 Release 12022-12-08
CVE-2022-39903 [LOW] CWE-200 CVE-2022-39903: Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attac
Improper access control vulnerability in RCS call prior to SMR Dec-2022 Release 1 allows local attackers to access RCS incoming call number.
cvelistv5nvd
CVE-2022-39913LOWCVSS 3.3≥ unspecified, < Android T(13)2022-12-08
CVE-2022-39913 [LOW] CWE-200 CVE-2022-39913: Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13)
Exposure of Sensitive Information to an Unauthorized Actor in Persona Manager prior to Android T(13) allows local attacker to access user profiles information.
cvelistv5nvd
CVE-2022-39895LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Dec-2022 Release 12022-12-08
CVE-2022-39895 [LOW] CWE-284 CVE-2022-39895: Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 a
Improper access control vulnerability in ContactListUtils in Phone prior to SMR Dec-2022 Release 1 allows to access contact group information via implicit intent.
cvelistv5nvd
CVE-2022-39912LOWCVSS 3.3≥ unspecified, < Android T(13)2022-12-08
CVE-2022-39912 [LOW] CWE-280 CVE-2022-39912: Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManag
Improper handling of insufficient permissions vulnerability in setSecureFolderPolicy in PersonaManagerService prior to Android T(13) allows local attackers to set some setting value in Secure folder.
cvelistv5nvd
CVE-2022-39894LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Dec-2022 Release 12022-12-08
CVE-2022-39894 [LOW] CWE-284 CVE-2022-39894: Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-20
Improper access control vulnerability in ContactListStartActivityHelper in Phone prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
cvelistv5nvd
CVE-2022-39896LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Dec-2022 Release 12022-12-08
CVE-2022-39896 [LOW] CWE-284 CVE-2022-39896: Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access
Improper access control vulnerabilities in Contacts prior to SMR Dec-2022 Release 1 allows to access sensitive information via implicit intent.
cvelistv5nvd
CVE-2022-39881CRITICALCVSS 9.1≥ Select devices using Exynos CP chipsets, < SMR Nov-2022 Release 12022-11-09
CVE-2022-39881 [CRITICAL] CWE-20 CVE-2022-39881: Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2
Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.
cvelistv5nvd
CVE-2022-39880HIGHCVSS 7.8≥ R(11), S(12), < SMR Nov-2022 Release 12022-11-09
CVE-2022-39880 [HIGH] CWE-20 CVE-2022-39880: Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows
Improper input validation vulnerability in DualOutFocusViewer prior to SMR Nov-2022 Release 1 allows local attacker to perform an arbitrary code execution.
cvelistv5nvd
CVE-2022-39883HIGHCVSS 7.8≥ Q(10), R(11), S(12), < SMR Nov-2022 Release 12022-11-09
CVE-2022-39883 [HIGH] CWE-285 CVE-2022-39883: Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows
Improper authorization vulnerability in StorageManagerService prior to SMR Nov-2022 Release 1 allows local attacker to call privileged API.
cvelistv5nvd
CVE-2022-39882HIGHCVSS 7.8≥ Q(10), R(11), S(12) , < SMR Nov-2022 Release 12022-11-09
CVE-2022-39882 [HIGH] CWE-787 CVE-2022-39882: Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov
Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.
cvelistv5nvd
CVE-2022-39886LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Nov-2022 Release 12022-11-09
CVE-2022-39886 [LOW] CWE-280 CVE-2022-39886: Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Re
Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022 Release 1 allows local attacker to access Device information.
cvelistv5nvd
CVE-2022-39885LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Nov-2022 Release 12022-11-09
CVE-2022-39885 [LOW] CWE-280 CVE-2022-39885: Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR
Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.
cvelistv5nvd
CVE-2022-39887LOWCVSS 3.3≥ Q(10), R(11), S(12), < SMR Nov-2022 Release 12022-11-09
CVE-2022-39887 [LOW] CWE-284 CVE-2022-39887: Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Rel
Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.
cvelistv5nvd
CVE-2022-39879LOWCVSS 3.3≥ R(11), S(12), < SMR Nov-2022 Release 12022-11-09
CVE-2022-39879 [LOW] CWE-285 CVE-2022-39879: Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local
Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.
cvelistv5nvd