CVE-2023-21422
- EPSS 0.06%
- Veröffentlicht 09.02.2023 19:15:14
- Zuletzt bearbeitet 21.11.2024 07:42:50
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
CVE-2021-25487
- EPSS 2.37%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 30.10.2025 15:36:23
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
CVE-2021-25489
- EPSS 0.36%
- Veröffentlicht 06.10.2021 18:15:09
- Zuletzt bearbeitet 30.10.2025 15:36:18
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
CVE-2021-25395
- EPSS 0.17%
- Veröffentlicht 11.06.2021 15:15:09
- Zuletzt bearbeitet 30.10.2025 15:36:28
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
CVE-2021-25394
- EPSS 0.62%
- Veröffentlicht 11.06.2021 15:15:08
- Zuletzt bearbeitet 30.10.2025 15:36:32
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
CVE-2021-25369
- EPSS 0.16%
- Veröffentlicht 26.03.2021 19:15:12
- Zuletzt bearbeitet 30.10.2025 15:37:05
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
CVE-2021-25370
- EPSS 0.24%
- Veröffentlicht 26.03.2021 19:15:12
- Zuletzt bearbeitet 14.01.2026 18:40:57
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
CVE-2021-25371
- EPSS 0.9%
- Veröffentlicht 26.03.2021 19:15:12
- Zuletzt bearbeitet 30.10.2025 15:36:48
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
CVE-2021-25372
- EPSS 0.9%
- Veröffentlicht 26.03.2021 19:15:12
- Zuletzt bearbeitet 14.01.2026 18:43:48
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
CVE-2021-25337
- EPSS 0.35%
- Veröffentlicht 04.03.2021 21:15:13
- Zuletzt bearbeitet 30.10.2025 15:37:12
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.