Filtered by vendor Samsung
Subscriptions
Filtered by product Mobile
Subscriptions
Total
35 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-21041 | 2 Google, Samsung | 3 Android, Mobile, Secure Folder | 2025-09-04 | 6.2 Medium |
Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information. | ||||
CVE-2023-21467 | 1 Samsung | 3 Exynos, Mobile, Samsung Mobile | 2025-09-04 | 4.6 Medium |
Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message. | ||||
CVE-2023-21468 | 1 Samsung | 2 Mobile, Samsung Mobile | 2025-09-04 | 5.9 Medium |
Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission. | ||||
CVE-2023-21477 | 1 Samsung | 2 Mobile, Samsung Mobile | 2025-09-04 | 7.9 High |
Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data. | ||||
CVE-2023-21480 | 1 Samsung | 3 Mobile, Samsung, Samsung Mobile | 2025-09-04 | 8.5 High |
Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities. | ||||
CVE-2025-21026 | 2 Google, Samsung | 3 Android, Mobile, Samsung Mobile | 2025-09-04 | 4 Medium |
Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call. | ||||
CVE-2025-21027 | 1 Samsung | 2 Mobile, Samsung Mobile | 2025-09-04 | 5.1 Medium |
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM. | ||||
CVE-2023-21469 | 2 Google, Samsung | 3 Android, Mobile, Samsung Mobile | 2025-09-04 | 4 Medium |
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action. | ||||
CVE-2025-21028 | 1 Samsung | 3 Mobile, Samsung, Samsung Mobile | 2025-09-04 | 5.5 Medium |
Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items. | ||||
CVE-2023-21479 | 2 Google, Samsung | 4 Android, Mobile, Samsung Mobile and 1 more | 2025-09-04 | 5.3 Medium |
Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule. | ||||
CVE-2025-21035 | 2 Google, Samsung | 5 Android, Calendar, Mobile and 2 more | 2025-09-04 | 4.6 Medium |
Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles. | ||||
CVE-2025-21032 | 1 Samsung | 3 Mobile, One Ui, Samsung Mobile | 2025-09-04 | 5.9 Medium |
Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions. | ||||
CVE-2025-20990 | 1 Samsung | 4 Android, Mobile, Samsung Mobile and 1 more | 2025-08-12 | 4 Medium |
Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier. | ||||
CVE-2025-20983 | 1 Samsung | 2 Android, Mobile | 2025-07-14 | 6.4 Medium |
Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||||
CVE-2014-8346 | 1 Samsung | 2 Findmymobile, Mobile | 2025-04-12 | N/A |
The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic. |