samsung Vulnerabilities and Affected Products
Vulnerabilities associated with Mobile Devices.
Products
Clear product- android44 vulnerabilities
- SmartThings Hub STH-ETH-25023 vulnerabilities
- Mobile Devices13 vulnerabilities
- Samsung11 vulnerabilities
- exynos_13809 vulnerabilities
- exynos_13308 vulnerabilities
- exynos_12807 vulnerabilities
- exynos_8507 vulnerabilities
- exynos_9806 vulnerabilities
- notes5 vulnerabilities
- samsung_mobile_devices5 vulnerabilities
- exynos_22004 vulnerabilities
- exynos_980_firmware4 vulnerabilities
- magician4 vulnerabilities
- exynos_10803 vulnerabilities
- exynos_1380_firmware3 vulnerabilities
- exynos_21003 vulnerabilities
- exynos_w9203 vulnerabilities
- Galaxy S93 vulnerabilities
- Samsung Galaxy Apps3 vulnerabilities
- exynos_1280_firmware2 vulnerabilities
- exynos_1330_firmware2 vulnerabilities
- exynos_14802 vulnerabilities
- exynos_850_firmware2 vulnerabilities
- exynos_91102 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-21043HIGH | Samsung Mobile Devices Out-of-Bounds Write VulnerabilityOut-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. CWE-787Sep 12, 2025 | CVSS8.8v3.1 | EPSS1.91% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-21042HIGH | Samsung Mobile Devices Out-of-Bounds Write VulnerabilityOut-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. CWE-787Sep 12, 2025 | CVSS8.8v3.1 | EPSS33.2% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-21492MEDIUM | Samsung Mobile Devices Insertion of Sensitive Information Into Log File VulnerabilityKernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. CWE-532May 4, 2023 | CVSS4.4v3.1 | EPSS2.55% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-22265MEDIUM | Samsung Mobile Devices Use-After-Free VulnerabilityAn improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution. | CVSS5.0v3.1 | EPSS0.392% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Samsung Mobile Devices Improper Input Validation VulnerabilityAssuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic. | CVSS3.3v3.1 | EPSS0.531% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2021-25487HIGH | Samsung Mobile Devices Out-of-Bounds Read VulnerabilityLack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer. CWE-125Oct 6, 2021 | CVSS7.3v3.1 | EPSS0.635% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25394MEDIUM | Samsung Mobile Devices Race Condition VulnerabilityA use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised. | CVSS6.4v3.1 | EPSS0.401% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25395MEDIUM | Samsung Mobile Devices Race Condition VulnerabilityA race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised. CWE-362Jun 11, 2021 | CVSS6.4v3.1 | EPSS0.366% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25372MEDIUM | Samsung Mobile Devices Improper Boundary Check VulnerabilityAn improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. | CVSS6.1v3.1 | EPSS0.804% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25371MEDIUM | Samsung Mobile Devices Unspecified VulnerabilityA vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. CWE-912Mar 26, 2021 | CVSS6.1v3.1 | EPSS0.802% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25370MEDIUM | Samsung Mobile Devices Memory Corruption VulnerabilityAn incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic. | CVSS6.1v3.1 | EPSS0.89% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25369MEDIUM | Samsung Mobile Devices Improper Access Control VulnerabilityAn improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. | CVSS6.2v3.1 | EPSS1.12% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25337MEDIUM | Samsung Mobile Devices Improper Access Control VulnerabilityImproper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files. | CVSS4.4v3.1 | EPSS2.83% | PoCs1 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |