Vulnerabilidades em Samsung Mobile

1.335 resultados
Análise Vexday

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2021-25375MEDIUMUsing predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emaEPSS 1.2%CVE-2023-42581HIGHImproper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to acEPSS 1.2%CVE-2021-25369MEDIUMAn improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.EPSS 1.1%KEVCVE-2023-42580HIGHImproper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to instEPSS 1.0%CVE-2021-25378MEDIUMImproper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.EPSS 1.0%CVE-2024-49415HIGHOut-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.EPSS 1.0%CVE-2021-25442Improper MDM policy management vulnerability in KME module prior to KCS version 1.39 allows MDM users to bypass Knox Manage authentication.EPSS 0.9%CVE-2022-22288HIGHImproper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.EPSS 0.9%CVE-2021-25370MEDIUMAn incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kEPSS 0.9%KEVCVE-2022-28544MEDIUMPath traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to accessEPSS 0.9%CVE-2022-33713Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information.EPSS 0.9%CVE-2022-30746HIGHMissing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript intEPSS 0.8%CVE-2022-39881MEDIUMImproper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to reEPSS 0.8%CVE-2021-25446Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loaEPSS 0.8%CVE-2021-25448Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.EPSS 0.8%CVE-2021-25372MEDIUMAn improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.EPSS 0.8%KEVCVE-2021-25371MEDIUMA vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.EPSS 0.8%KEVCVE-2021-25508MEDIUMImproper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key withouEPSS 0.8%CVE-2021-25447Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion EPSS 0.8%CVE-2021-25425Improper check vulnerability in Samsung Health prior to version 6.17 allows attacker to read internal cache data via exported component.EPSS 0.8%