Sm4635
Vendor:
First CVE: Sep 2, 2024 · Active for 1 year
77
Total CVEs
More Total CVEs than 99% of tracked products
25.7
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 59% of tracked products
2.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Sm4635 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 2, 2024
22 months ago
Most Recent CVE
Feb 2, 2026
172 days ago
CVE Severity & Scoring
Sm463577 CVEs
21%
75%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local60 (77.9%)
Network16 (20.8%)
Unknown0 (0.0%)
Physical1 (1.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low75 (97.4%)
High2 (2.6%)
Unknown0 (0.0%)
User Interaction
None75 (97.4%)
Unknown0 (0.0%)
Required2 (2.6%)
Privileges Required
Low51 (66.2%)
High5 (6.5%)
None21 (27.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (77 CVEs).
77 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-21479HIGH Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | Jun 3, 2025 | 8.6 | 69 | YES | NO |
CVE-2025-21480HIGH Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | Jun 3, 2025 | 8.6 | 67 | YES | NO |
CVE-2025-27034CRITICAL Memory corruption while selecting the PLMN from SOR failed list. | Sep 24, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-21483CRITICAL Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. | Sep 24, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-47345HIGH Cryptographic issue may occur while encrypting license data. | Jan 7, 2026 | 8.4 | 27 | NO | NO |
CVE-2025-21488HIGH Information disclosure while decoding this RTP packet headers received by UE from the network when the padding bit is set. | Sep 24, 2025 | 8.2 | 27 | NO | NO |
CVE-2025-21487HIGH Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. | Sep 24, 2025 | 8.2 | 27 | NO | NO |
CVE-2025-47366HIGH Cryptographic issue when a Trusted Zone with outdated code is triggered by a HLOS providing incorrect input. | Feb 2, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-47339HIGH Memory corruption while deinitializing a HDCP session. | Jan 7, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-21481HIGH Memory corruption while performing private key encryption in trusted application. | Sep 24, 2025 | 7.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (77 CVEs).
CISA KEV
2 CVEs
2.6% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (77 CVEs).
Media Mentions
Signals from CVEs in this product scope (77 CVEs).
Top CNAs Publishing CVEs For Sm4635
Top CWEs
Versions
No cataloged versions.