Samsung Android vulnerabilities
465 known vulnerabilities affecting samsung/android.
Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66
Vulnerabilities
Page 1 of 24
CVE-2025-21042P1CRITICALCVSS 9.8KEVPoCv13.0v14.0+1 more2025-09-12
CVE-2025-21042 [CRITICAL] CWE-787 CVE-2025-21042: Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attacker
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
nvd
CVE-2025-21043P1CRITICALCVSS 9.8KEVv13.0v14.0+2 more2025-09-12
CVE-2025-21043 [CRITICAL] CWE-787 CVE-2025-21043: Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attacker
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
nvd
CVE-2021-25337P1HIGHCVSS 7.1KEVv9.0v10.0+1 more2021-03-04
CVE-2021-25337 [HIGH] CWE-269 CVE-2021-25337: Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
nvd
CVE-2021-25489P2MEDIUMCVSS 5.5KEVv8.1v9.0+2 more2021-10-06
CVE-2021-25489 [MEDIUM] CWE-20 CVE-2021-25489: Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR
Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
nvd
CVE-2021-25487P2HIGHCVSS 7.8KEVv8.1v9.0+2 more2021-10-06
CVE-2021-25487 [HIGH] CWE-125 CVE-2021-25487: Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
nvd
CVE-2021-25372P2MEDIUMCVSS 6.7KEVv10.0v11.02021-03-26
CVE-2021-25372 [MEDIUM] CWE-787 CVE-2021-25372: An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
nvd
CVE-2021-25394P2MEDIUMCVSS 6.4KEVv8.1v9.0+2 more2021-06-11
CVE-2021-25394 [MEDIUM] CWE-416 CVE-2021-25394: A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Releas
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
nvd
CVE-2021-25369P2MEDIUMCVSS 5.5KEVv8.0v8.1+2 more2021-03-26
CVE-2021-25369 [MEDIUM] CWE-200 CVE-2021-25369: An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sen
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.
nvd
CVE-2021-25370P2MEDIUMCVSS 4.4KEVv8.0v8.1+3 more2021-03-26
CVE-2021-25370 [MEDIUM] CWE-416 CVE-2021-25370: An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 r
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
nvd
CVE-2021-25371P2MEDIUMCVSS 6.7KEVv10.0v11.02021-03-26
CVE-2021-25371 [MEDIUM] CWE-912 CVE-2021-25371: A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF li
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
nvd
CVE-2021-25395P2MEDIUMCVSS 6.4KEVv8.1v9.0+2 more2021-06-11
CVE-2021-25395 [MEDIUM] CWE-362 CVE-2021-25395: A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to byp
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
nvd
CVE-2023-21492P2MEDIUMCVSS 4.4KEVv11.0v12.0+1 more2023-05-04
CVE-2023-21492 [MEDIUM] CWE-532 CVE-2023-21492: Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged loca
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
nvd
CVE-2024-49415P2CRITICALCVSS 9.8v12.0v13.0+1 more2024-12-03
CVE-2024-49415 [CRITICAL] CWE-787 CVE-2024-49415: Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute
Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.
nvd
CVE-2023-30699P3CRITICALCVSS 9.8v11.0v12.0+1 more2023-08-10
CVE-2023-30699 [CRITICAL] CWE-787 CVE-2023-30699: Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023
Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.
nvd
CVE-2026-20973P3CRITICALCVSS 9.1v13.0v14.0+2 more2026-01-09
CVE-2026-20973 [CRITICAL] CWE-125 CVE-2026-20973: Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker
Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory.
nvd
CVE-2023-21494P3CRITICALCVSS 9.8v13.02023-05-04
CVE-2023-21494 [CRITICAL] CWE-20 CVE-2023-21494: Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior
Potential buffer overflow vulnerability in auth api in mm_Authentication.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
nvd
CVE-2023-21504P3CRITICALCVSS 9.8v11.0v12.0+1 more2023-05-04
CVE-2023-21504 [CRITICAL] CWE-20 CVE-2023-21504: Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR Ma
Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
nvd
CVE-2023-21503P3CRITICALCVSS 9.8v13.02023-05-04
CVE-2023-21503 [CRITICAL] CWE-20 CVE-2023-21503: Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to S
Potential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
nvd
CVE-2024-34593P3HIGHCVSS 8.8v12.0v13.0+1 more2024-07-02
CVE-2024-34593 [HIGH] CVE-2024-34593: Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024
Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34619P3HIGHCVSS 8.8v12.0v13.0+1 more2024-08-07
CVE-2024-34619 [HIGH] CVE-2024-34619: Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to ex
Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
nvd
1 / 24Next →