Vulnerabilidades em Samsung Mobile

1.316 resultados
Análise Vexday

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2025-20897MEDIUMImproper access control in Secure Folder prior to version 1.9.20.50 in Android 14, 1.8.11.0 in Android 13, and 1.7.04.0 in Android 12 allowsEPSS 0.1%CVE-2024-20847MEDIUMImproper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allows local attackers to read sdcard informaEPSS 0.1%CVE-2025-21015MEDIUMPath Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.EPSS 0.1%CVE-2024-34662MEDIUMImproper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select AndEPSS 0.1%CVE-2024-34638MEDIUMImproper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded apEPSS 0.1%CVE-2024-20834LOWThe sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address wiEPSS 0.1%CVE-2024-34610MEDIUMImproper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.EPSS 0.1%CVE-2024-20835MEDIUMImproper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local attackers to execute priEPSS 0.1%CVE-2025-20928MEDIUMOut-of-bounds read in parsing wbmp image in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access out-of-bounds memory.EPSS 0.1%CVE-2025-20933MEDIUMOut-of-bounds read in parsing bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-of-bounds memory.EPSS 0.1%CVE-2025-20925MEDIUMOut-of-bounds read in applying binary of text data in Samsung Notes prior to version 4.4.26.71 allows local attackers to potentially read meEPSS 0.1%CVE-2025-20930MEDIUMOut-of-bounds read in parsing jpeg image in Samsung Notes prior to version 4.4.26.71 allows local attackers to read out-of-bounds memory.EPSS 0.1%CVE-2025-21017MEDIUMOut-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-EPSS 0.1%CVE-2024-34640LOWImproper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of prEPSS 0.1%CVE-2025-20932MEDIUMOut-of-bounds read in parsing rle of bmp image in Samsung Notes prior to version 4.4.26.71 allows local attackers to혻read out-of-bounds memoEPSS 0.1%CVE-2025-20927MEDIUMOut-of-bounds read in parsing image data in Samsung Notes prior to vaersion 4.4.26.71 allows local attackers to access out-of-bounds memory.EPSS 0.1%CVE-2024-34620HIGHImproper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.EPSS 0.1%CVE-2024-34677MEDIUMExposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitiEPSS 0.1%CVE-2024-20808MEDIUMImproper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.EPSS 0.1%CVE-2024-20809MEDIUMImproper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.EPSS 0.1%