target entity

Mobile Devices

13 source-linked records in the current knowledge graph.

high

CVE-2025-21042: Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-21042EPSS 11.6%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2025-21043: Samsung Mobile Devices Out-of-Bounds Write Vulnerability

Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-21043EPSS 1.4%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2022-22265: Samsung Mobile Devices Use-After-Free Vulnerability

Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory write and code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-22265EPSS 0.4%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25487: Samsung Mobile Devices Out-of-Bounds Read Vulnerability

Samsung mobile devices contain an out-of-bounds read vulnerability within the modem interface driver due to a lack of boundary checking of a buffer in set_skb_priv(), leading to remote code execution by dereference of an invalid function pointer. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVE-2021-25487EPSS 0.6%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25489: Samsung Mobile Devices Improper Input Validation Vulnerability

Samsung mobile devices contain an improper input validation vulnerability within the modem interface driver that results in a format string bug leading to kernel panic. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVE-2021-25489EPSS 0.5%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25394: Samsung Mobile Devices Race Condition Vulnerability

Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVE-2021-25394EPSS 0.4%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25395: Samsung Mobile Devices Race Condition Vulnerability

Samsung mobile devices contain a race condition vulnerability within the MFC charger driver that leads to a use-after-free allowing for a write given a radio privilege is compromised. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVE-2021-25395EPSS 0.4%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25371: Samsung Mobile Devices Unspecified Vulnerability

Samsung mobile devices contain an unspecified vulnerability within DSP driver that allows attackers to load ELF libraries inside DSP. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable

CVE-2021-25371EPSS 0.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25337: Samsung Mobile Devices Improper Access Control Vulnerability

Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370. Required action: Apply updates per vendor instructions.

CVE-2021-25337CVE-2021-25369EPSS 2.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25369: Samsung Mobile Devices Improper Access Control Vulnerability

Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370. Required action: Apply updates per vendor instructions.

CVE-2021-25337CVE-2021-25369EPSS 2.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution
high

CVE-2021-25370: Samsung Mobile Devices Memory Corruption Vulnerability

Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369. Required action: Apply updates per vendor instructions.

CVE-2021-25337CVE-2021-25369EPSS 2.8%Mobile DevicesSamsung
CISA KEV ↗ · unattributed attribution