Vulnerabilities in Samsung Mobile

1,316 results
Vexday analysis

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2024-20867MEDIUMImproper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive informatiEPSS 0.2%CVE-2024-34597MEDIUMImproper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandEPSS 0.2%CVE-2024-20881MEDIUMImproper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local privileged attackers lead to potential aEPSS 0.2%CVE-2023-21458MEDIUMImproper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn offEPSS 0.2%CVE-2024-20901MEDIUMImproper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-ofEPSS 0.2%CVE-2026-20986MEDIUMPath traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members.EPSS 0.2%CVE-2023-30675MEDIUMImproper authentication in Samsung Pass prior to version 4.2.03.1 allows local attacker to access stored account information when Samsung WaEPSS 0.2%CVE-2024-20831MEDIUMStack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.EPSS 0.2%CVE-2024-49401MEDIUMImproper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities.EPSS 0.2%CVE-2023-21482MEDIUMMissing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 1EPSS 0.2%CVE-2024-34602LOWUse of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitiEPSS 0.2%CVE-2022-39872MEDIUMImproper restriction of broadcasting Intent in ShareLive prior to version 13.2.03.5 leaks MAC address of the connected Bluetooth device.EPSS 0.2%CVE-2024-49412MEDIUMImproper input validation in Settings prior to SMR Dec-2024 Release 1 allows local attackers to broadcast signal for discovering Bluetooth oEPSS 0.2%CVE-2024-34630MEDIUMOut-of-bounds read in applying own binary with textbox in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially reaEPSS 0.2%CVE-2024-34624MEDIUMOut-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.EPSS 0.2%CVE-2024-20857MEDIUMImproper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to acceEPSS 0.2%CVE-2024-34625MEDIUMOut-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memorEPSS 0.2%CVE-2024-34626MEDIUMOut-of-bounds read in applying own binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.EPSS 0.2%CVE-2023-21491HIGHImproper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with sEPSS 0.2%CVE-2024-34628MEDIUMOut-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memorEPSS 0.2%