Vulnerabilidades em Samsung Mobile

1.391 resultados
Análise Vexday

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2022-22284MEDIUMImproper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authenticationEPSS 0.2%CVE-2021-25454LOWOOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac EPSS 0.2%CVE-2022-25825MEDIUMImproper access control vulnerability in Samsung Account prior to version 13.1.0.1 allows attackers to access to the authcode for sign-in.EPSS 0.2%CVE-2021-25341MEDIUMCalling of non-existent provider in S Assistant prior to version 6.5.01.22 allows unauthorized actions including denial of service attack byEPSS 0.2%CVE-2024-34642MEDIUMImproper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.EPSS 0.2%CVE-2024-20889MEDIUMImproper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.EPSS 0.2%CVE-2021-25342MEDIUMCalling of non-existent provider in SMP sdk prior to version 3.0.9 allows unauthorized actions including denial of service attack by hijackiEPSS 0.2%CVE-2021-25343MEDIUMCalling of non-existent provider in Samsung Members prior to version 2.4.81.13 (in Android O(8.1) and below) and 3.8.00.13 (in Android P(9.0EPSS 0.2%CVE-2024-20827MEDIUMImproper access control vulnerability in Samsung Gallery prior to version 14.5.04.4 allows physical attackers to access the picture using phEPSS 0.2%CVE-2021-25352MEDIUMUsing PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijackinEPSS 0.2%CVE-2021-25524MEDIUMInsecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.EPSS 0.2%CVE-2021-25433—Improper authorization vulnerability in Tizen factory reset policy prior to Firmware update JUL-2021 Release allows untrusted applications tEPSS 0.2%CVE-2021-25523MEDIUMInsecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.EPSS 0.2%CVE-2025-21035MEDIUMImproper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers EPSS 0.2%CVE-2023-42555MEDIUMUse of implicit intent for sensitive communication vulnerability in EasySetup prior to version 11.1.13 allows attackers to get the bluetoothEPSS 0.2%CVE-2023-21512LOWImproper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notiEPSS 0.2%CVE-2022-36853LOWIntent redirection in Photo Editor prior to SMR Sep-2022 Release 1 allows attacker to get sensitive information.EPSS 0.2%CVE-2024-20871MEDIUMImproper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the facEPSS 0.2%CVE-2024-20845HIGHOut-of-bounds write vulnerability while releasing memory in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arEPSS 0.2%CVE-2024-20882MEDIUMOut-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.EPSS 0.2%