Vulnerabilidades em Samsung Mobile

1.391 resultados
Análise Vexday

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2026-21035MEDIUMImproper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.EPSS 0.3%CVE-2024-20887MEDIUMArbitrary directory creation in GalaxyBudsManager PC prior to version 2.1.240315.51 allows attacker to create arbitrary directory.EPSS 0.3%CVE-2021-25507MEDIUMImproper authorization vulnerability in Samsung Flow mobile application prior to 4.8.03.5 allows Samsung Flow PC application connected with EPSS 0.3%CVE-2025-21055MEDIUMOut-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memorEPSS 0.3%CVE-2023-21481MEDIUMImproper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitivEPSS 0.3%CVE-2024-20856MEDIUMImproper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder witEPSS 0.3%CVE-2026-20985HIGHImproper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrarEPSS 0.3%CVE-2026-21061MEDIUMImproper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User inEPSS 0.3%CVE-2021-25494MEDIUMA possible buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary coEPSS 0.3%CVE-2022-27823MEDIUMImproper size check in sapefd_parse_meta_HEADER_old function of libsapeextractor library prior to SMR Apr-2022 Release 1 allows out of boundEPSS 0.3%CVE-2021-25351LOWImproper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackeEPSS 0.3%CVE-2022-30713HIGHImproper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.EPSS 0.3%CVE-2022-30711HIGHImproper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.EPSS 0.3%CVE-2022-30710HIGHImproper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.EPSS 0.3%CVE-2023-21450LOWMissing Authorization vulnerability in One Hand Operation + prior to version 6.1.21 allows multi-users to access owner's widget without EPSS 0.3%CVE-2021-25495HIGHA possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitraEPSS 0.3%CVE-2021-25496HIGHA possible buffer overflow vulnerability in maetd_dec_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61EPSS 0.3%CVE-2021-25497HIGHA possible buffer overflow vulnerability in maetd_cpy_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61EPSS 0.3%CVE-2021-25498HIGHA possible buffer overflow vulnerability in maetd_eco_cb_mode of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.EPSS 0.3%CVE-2026-20969LOWImproper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User inEPSS 0.3%