Vulnerabilidades em Samsung Mobile

1.391 resultados
Análise Vexday

Samsung Mobile acumula 1.316 CVEs catalogadas, com 13 confirmadas em exploração ativa pelo CISA KEV — uma taxa 2,2 vezes acima da média geral do catálogo, o que indica exposição operacional relevante e exige atenção prioritária na gestão de patches. O tipo de falha mais recorrente é CWE-20 (validação inadequada de entrada), sugerindo fragilidades sistemáticas no tratamento de dados externos que tendem a gerar superfícies amplas de ataque. A CVE mais perigosa em exploração ativa no momento é CVE-2025-21042, com escore EPSS de 0,1161, enquanto 34 novas vulnerabilidades surgiram nos últimos 90 dias, sinalizando um ritmo de descoberta contínuo que demanda monitoramento frequente. Com apenas 3 CVEs acompanhadas de PoC pública e EPSS máximo observado de 0,1289, o risco de exploração massiva imediata é moderado, mas a combinação de falhas ativas confirmadas e volume crescente de novas entradas justifica ciclos curtos de atualização de firmware em ambientes corporativos.

CVE-2022-27837MEDIUMA vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attEPSS 0.6%CVE-2022-24003MEDIUMExposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby EPSS 0.6%CVE-2021-25478HIGHA possible stack-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and EPSS 0.6%CVE-2021-25479HIGHA possible heap-based buffer overflow vulnerability in Exynos CP Chipset prior to SMR Oct-2021 Release 1 allows arbitrary memory write and cEPSS 0.6%CVE-2023-21516HIGHXSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from EPSS 0.5%CVE-2026-20998HIGHImproper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.EPSS 0.5%CVE-2022-39862MEDIUMImproper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and 3.3.03.66 in Android S(12) allows unauthorEPSS 0.5%CVE-2021-25384CRITICALAn improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor library prior to SMR MAY-EPSS 0.5%CVE-2021-25383CRITICALAn improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers EPSS 0.5%CVE-2025-21079HIGHImproper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL and launch arbitraryEPSS 0.5%CVE-2024-34619HIGHImproper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privileEPSS 0.5%CVE-2022-30738MEDIUMImproper check in Loader in Samsung Internet prior to 17.0.1.69 allows attackers to spoof address bar via executing script.EPSS 0.5%CVE-2022-30733MEDIUMSensitive information exposure in Sign-in log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone nEPSS 0.5%CVE-2022-30734MEDIUMSensitive information exposure in Sign-out log in Samsung Account prior to version 13.2.00.6 allows attackers to get an user email or phone EPSS 0.5%CVE-2022-30737MEDIUMImplicit Intent hijacking vulnerability in Samsung Account prior to version 13.2.00.6 allows attackers to get email ID.EPSS 0.5%CVE-2021-25489LOWAssuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format stEPSS 0.5%KEVCVE-2022-24002MEDIUMImproper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionEPSS 0.5%CVE-2022-26096MEDIUMNull pointer dereference vulnerability in parser_ispe function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds writEPSS 0.5%CVE-2022-26093MEDIUMNull pointer dereference vulnerability in parser_irot function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds writEPSS 0.5%CVE-2022-26095MEDIUMNull pointer dereference vulnerability in parser_colr function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds writEPSS 0.5%