Samsung Mobile

First CVE: Mar 2, 2021Active for: 5 years
1,335
CVEs Published
More CVEs Published than 92% of tracked CNAs
222.5
Avg CVEs / Year
More Avg CVEs / Year than 95% of tracked CNAs
5.9
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked CNAs
1.0%
In CISA KEV
Higher KEV Rate than 88% of tracked CNAs

Trends Over Time

The number and severity of CVEs published by Samsung Mobile over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 2, 2021
5 years ago
Most Recent CVE
Jul 10, 2026
15 days ago

Top CVEs

All CVEs published by Samsung Mobile as a CNA, regardless of affected vendor or product.

1,335 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
Sep 12, 20259.887YESNO
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
Sep 12, 20259.875YESNO
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code execution.
Jan 10, 20227.863YESNO
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dere
Oct 6, 20217.863YESNO
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
Mar 26, 20216.760YESNO
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
Mar 4, 20217.160YESNO
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
Jun 11, 20216.458YESNO
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
Mar 26, 20216.758YESNO
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
Jun 11, 20216.457YESNO
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
Mar 26, 20215.556YESNO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA1,335 CVEs
Severity distribution among all CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local963 (72.1%)
Network211 (15.8%)
Unknown0 (0.0%)
Physical126 (9.4%)
Adjacent Network35 (2.6%)
Attack Complexity
Low1,318 (98.7%)
High17 (1.3%)
Unknown0 (0.0%)
User Interaction
None1,198 (89.7%)
Unknown0 (0.0%)
Required137 (10.3%)
Privileges Required
Low789 (59.1%)
High96 (7.2%)
None450 (33.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (1335 CVEs).

CISA KEV
13 CVEs
1.0% of CVEs· 88th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Samsung Mobile as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Samsung Mobile as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs