Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Notes HIGH 7.1
CVE-2025-21069

Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Fix: 4.4.30.63+
Fix from $1,950 2025-10-10
Notes MEDIUM 5.5
CVE-2025-21070

Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.

Fix: 4.4.30.63+
Fix from $1,600 2025-10-10
Smart Switch HIGH 7.8
CVE-2025-21062

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring applicatio…

Fix: 3.7.67.2+
Fix from $1,950 2025-10-10
Notes HIGH 7.1
CVE-2025-21066

Out-of-bounds read in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.

Fix: 4.4.30.63+
Fix from $1,950 2025-10-10
Smart Switch MEDIUM 6.5
CVE-2025-21064

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

Fix: 3.7.67.2+
Fix from $1,600 2025-10-10
Smart Switch MEDIUM 5.5
CVE-2025-21061

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access sensitive data. User interactio…

Fix: 3.7.67.2+
Fix from $1,600 2025-10-10
Android HIGH 7.5
CVE-2025-21055

Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.

Mitigation only
Fix from $1,950 2025-10-10
Android MEDIUM 5.5
CVE-2025-21054

Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access…

Mitigation only
Fix from $1,600 2025-10-10
Health MEDIUM 5.5
CVE-2025-21059

Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.

Fix: 6.30.5.105+
Fix from $1,600 2025-10-10
Smart Switch MEDIUM 5.5
CVE-2025-21060

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.67.2 allows local attackers to access backup data from applications. …

Fix: 3.7.67.2+
Fix from $1,600 2025-10-10
Android HIGH 7.8
CVE-2025-21048

Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2025-10-10
Android HIGH 7.8
CVE-2025-21051

Out-of-bounds write in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to write out-of-bound…

Mitigation only
Fix from $1,950 2025-10-10
Android HIGH 7.8
CVE-2025-21052

Out-of-bounds write under specific condition in the pre-processing of JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attack…

Mitigation only
Fix from $1,950 2025-10-10
Android HIGH 7.8
CVE-2025-21053

Out-of-bounds write in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to cause memory corr…

Mitigation only
Fix from $1,950 2025-10-10
Android MEDIUM 5.5
CVE-2025-21049

Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is re…

Mitigation only
Fix from $1,600 2025-10-10
Android MEDIUM 5.5
CVE-2025-21050

Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.

Mitigation only
Fix from $1,600 2025-10-10
Android MEDIUM 6.8
CVE-2025-21047

Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.

Mitigation only
Fix from $1,600 2025-10-10
Wear Os MEDIUM 5.5
CVE-2025-21045

Insecure storage of sensitive information in Galaxy Watch prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information.

Mitigation only
Fix from $1,600 2025-10-10
Android CRITICAL 9.8
CVE-2025-21042 KEVEPSS 33%

Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.

Mitigation only
Fix from $2,300 2025-09-12
Android CRITICAL 9.8
CVE-2025-21043 KEV

Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.

Mitigation only
Fix from $2,300 2025-09-12
Good Lock MEDIUM 5.5
CVE-2024-34598

Improper export of component in GoodLock prior to version 2.2.04.95 allows local attackers to install arbitrary applications from Galaxy Store.

Fix: 2.2.04.95+
Fix from $1,600 2025-09-04
Android MEDIUM 5.5
CVE-2025-21041

Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.

Fix: 16.0+
Fix from $1,600 2025-09-03
Android HIGH 7.8
CVE-2025-21034

Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.

Mitigation only
Fix from $1,950 2025-09-03
Notes MEDIUM 5.0
CVE-2025-21036

Improper access control in Samsung Notes prior to version 4.4.30.63 allows local privileged attackers to access exported note files. User interaction…

Fix: 4.4.30.63+
Fix from $1,600 2025-09-03
Android MEDIUM 6.8
CVE-2025-21032

Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.

Mitigation only
Fix from $1,600 2025-09-03
Android MEDIUM 5.5
CVE-2025-21033

Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.

Mitigation only
Fix from $1,600 2025-09-03
Android MEDIUM 6.8
CVE-2025-21031

Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.

Mitigation only
Fix from $1,600 2025-09-03
Android MEDIUM 5.5
CVE-2025-21028

Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.

Mitigation only
Fix from $1,600 2025-09-03
Galaxy Store MEDIUM 5.5
CVE-2023-21483

Improper Access Control vulnerability in Galaxy Store prior to version 4.5.53.6 allows local attacker to access protected data using exported service.

Fix: 4.5.53.6+
Fix from $1,600 2025-09-03
Android HIGH 7.8
CVE-2023-21480

Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.

Mitigation only
Fix from $1,950 2025-09-03