Samsung Mobile
First CVE: Mar 2, 2021Active for: 5 years
1,335
CVEs Published
More CVEs Published than 92% of tracked CNAs
222.5
Avg CVEs / Year
More Avg CVEs / Year than 95% of tracked CNAs
5.9
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked CNAs
1.0%
In CISA KEV
Higher KEV Rate than 88% of tracked CNAs
Trends Over Time
The number and severity of CVEs published by Samsung Mobile over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2021
5 years ago
Most Recent CVE
Jul 10, 2026
15 days ago
Top CVEs
All CVEs published by Samsung Mobile as a CNA, regardless of affected vendor or product.
1,335 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-21042CRITICAL Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | Sep 12, 2025 | 9.8 | 87 | YES | NO |
CVE-2025-21043CRITICAL Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. | Sep 12, 2025 | 9.8 | 75 | YES | NO |
CVE-2022-22265HIGH An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution. | Jan 10, 2022 | 7.8 | 63 | YES | NO |
CVE-2021-25487HIGH Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dere | Oct 6, 2021 | 7.8 | 63 | YES | NO |
CVE-2021-25372MEDIUM An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. | Mar 26, 2021 | 6.7 | 60 | YES | NO |
CVE-2021-25337HIGH Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files. | Mar 4, 2021 | 7.1 | 60 | YES | NO |
CVE-2021-25394MEDIUM A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised. | Jun 11, 2021 | 6.4 | 58 | YES | NO |
CVE-2021-25371MEDIUM A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. | Mar 26, 2021 | 6.7 | 58 | YES | NO |
CVE-2021-25395MEDIUM A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised. | Jun 11, 2021 | 6.4 | 57 | YES | NO |
CVE-2021-25369MEDIUM An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. | Mar 26, 2021 | 5.5 | 56 | YES | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA1,335 CVEs
19%
48%
29%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local963 (72.1%)
Network211 (15.8%)
Unknown0 (0.0%)
Physical126 (9.4%)
Adjacent Network35 (2.6%)
Attack Complexity
Low1,318 (98.7%)
High17 (1.3%)
Unknown0 (0.0%)
User Interaction
None1,198 (89.7%)
Unknown0 (0.0%)
Required137 (10.3%)
Privileges Required
Low789 (59.1%)
High96 (7.2%)
None450 (33.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (1335 CVEs).
CISA KEV
13 CVEs
1.0% of CVEs· 88th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Samsung Mobile as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Samsung Mobile as a CNA — matched by CVE ID, not by organization name.