Sun Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Sun products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
19
In CISA KEV
18
Beyond CISA KEV
1
Sensor Observed
0
Virtual Patch Available
0
Sun KEVs Added by Year
19 Sun KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-34068
Samsung WLAN AP WEA453e < 5.2.4.T1 Unauthenticated RCE via command1 and command2 Parameters |
WLAN AP WEA453e | High | Not in CISA | 16 Feb 2026 |
|
CVE-2024-7399
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to... |
MagicINFO 9 Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-21042
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. |
Samsung Mobile Devices | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-21043
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. |
Samsung Mobile Devices | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-4632
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to... |
MagicINFO 9 Server | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2019-16256
Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location... |
SIMalliance Toolbox Browser | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2008-3431
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and... |
xVM VirtualBox | Confirmed | In CISA | 03 Mar 2022 |
|
CVE-2021-25370
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel... |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2021-25369
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace. |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2021-25337
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or... |
Samsung Mobile Devices | Confirmed | In CISA | 08 Nov 2022 |
|
CVE-2023-21492
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. |
Samsung Mobile Devices | Confirmed | In CISA | 19 May 2023 |
|
CVE-2021-25372
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25371
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25395
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25394
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25489
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2021-25487
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in... |
Samsung Mobile Devices | Confirmed | In CISA | 29 Jun 2023 |
|
CVE-2022-22265
An improper check or handling of exceptional conditions in NPU driver prior to SMR Jan-2022 Release 1 allows arbitrary memory write and code... |
Samsung Mobile Devices | Confirmed | In CISA | 18 Sep 2023 |
|
CVE-2021-36380
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi. |
SureLine | Confirmed | In CISA | 05 Mar 2024 |
Common Vulnerability Classes (CWE)
- CWE-703 — Improper Check or Handling of Exceptional Conditions 3
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 2
- CWE-787 — Out-of-bounds Write 2
- CWE-269 — Improper Privilege Management 1
- CWE-306 — Missing Authentication for Critical Function 1
- CWE-362 — Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') 1
- CWE-416 — Use After Free 1
- CWE-434 — Unrestricted Upload of File with Dangerous Type 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology