cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 10 of 24
CVE-2026-21007P4MEDIUMCVSS 6.8v14.0v15.0+1 more2026-04-13
CVE-2026-21007 [MEDIUM] CWE-754 CVE-2026-21007: Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows phys Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.
nvd
CVE-2023-42557P4MEDIUMCVSS 6.7≥ 12.0, < 14.0v14.02023-12-05
CVE-2023-42557 [MEDIUM] CWE-787 CVE-2023-42557: Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system at Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.
nvd
CVE-2024-20863P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-07
CVE-2024-20863 [MEDIUM] CWE-787 CVE-2024-20863: Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privil Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.
nvd
CVE-2024-20843P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-04-02
CVE-2024-20843 [MEDIUM] CWE-787 CVE-2024-20843: Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-202 Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code.
nvd
CVE-2024-20866P4MEDIUMCVSS 6.6v12.0v13.02024-05-07
CVE-2024-20866 [MEDIUM] CVE-2024-20866: Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical a Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.
nvd
CVE-2024-20803P4MEDIUMCVSS 6.5v11.0v12.0+2 more2024-01-04
CVE-2024-20803 [MEDIUM] CWE-287 CVE-2024-20803: Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 a Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
nvd
CVE-2023-30707P4HIGHCVSS 7.1v11.0v12.0+1 more2023-09-06
CVE-2023-30707 [HIGH] CVE-2023-30707: Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to S Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege.
nvd
CVE-2023-30643P4HIGHCVSS 7.1v11.0v12.0+1 more2023-07-06
CVE-2023-30643 [HIGH] CWE-306 CVE-2023-30643: Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows Missing authentication vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to delete arbitrary non-preloaded applications.
nvd
CVE-2023-21489P4MEDIUMCVSS 6.8v11.0v12.0+1 more2023-05-04
CVE-2023-21489 [MEDIUM] CWE-787 CVE-2023-21489: Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physic Heap out-of-bounds write vulnerability in bootloader prior to SMR May-2023 Release 1 allows a physical attacker to execute arbitrary code.
nvd
CVE-2024-20880P4MEDIUMCVSS 6.8v12.0v13.0+1 more2024-06-04
CVE-2024-20880 [MEDIUM] CWE-787 CVE-2024-20880: Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physi Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.
nvd
CVE-2026-21011P4MEDIUMCVSS 6.8v14.0v15.0+1 more2026-04-13
CVE-2026-21011 [MEDIUM] CWE-732 CVE-2026-21011: Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allo Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.
nvd
CVE-2025-21031P4MEDIUMCVSS 6.8v13.0v14.0+2 more2025-09-03
CVE-2025-21031 [MEDIUM] CWE-284 CVE-2025-21031: Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.
nvd
CVE-2023-42565P4MEDIUMCVSS 6.7≥ 13.0, < 14.0v14.02023-12-05
CVE-2023-42565 [MEDIUM] CVE-2023-42565: Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local a Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.
nvd
CVE-2024-20881P4MEDIUMCVSS 6.7v12.0v13.02024-06-04
CVE-2024-20881 [MEDIUM] CVE-2024-20881: Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local privileged attackers lead to potential arbitrary code execution.
nvd
CVE-2024-20831P4MEDIUMCVSS 6.7v11.0v12.0+2 more2024-03-05
CVE-2024-20831 [MEDIUM] CWE-787 CVE-2024-20831: Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privilege Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.
nvd
CVE-2025-20937P4MEDIUMCVSS 6.7v13.0v14.0+1 more2025-05-07
CVE-2025-20937 [MEDIUM] CWE-787 CVE-2025-20937: Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged at Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2023-42531P4HIGHCVSS 7.1v11.0v12.0+1 more2023-11-07
CVE-2023-42531 [HIGH] CWE-287 CVE-2023-42531: Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local a Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.
nvd
CVE-2023-52432P4HIGHCVSS 7.1v13.0v14.02024-03-05
CVE-2023-52432 [HIGH] CWE-787 CVE-2023-52432: Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 a Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2025-20948P4HIGHCVSS 7.1v13.0v14.0+1 more2025-04-08
CVE-2025-20948 [HIGH] CWE-125 CVE-2025-20948: Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allo Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
nvd
CVE-2025-21015P4HIGHCVSS 7.1v15.02025-08-06
CVE-2025-21015 [HIGH] CWE-22 CVE-2025-21015: Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
nvd