cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 11 of 24
CVE-2024-20879P4HIGHCVSS 7.1v12.0v13.0+1 more2024-06-04
CVE-2024-20879 [HIGH] CVE-2024-20879: Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows loca Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2025-20988P4HIGHCVSS 7.1v13.0v14.0+1 more2025-06-04
CVE-2025-20988 [HIGH] CWE-125 CVE-2025-20988: Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged a Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
nvd
CVE-2023-42533P4MEDIUMCVSS 6.8v12.0v13.02023-11-07
CVE-2023-42533 [MEDIUM] CVE-2023-42533: Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physica Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.
nvd
CVE-2026-21009P4MEDIUMCVSS 6.8v14.0v15.0+1 more2026-04-13
CVE-2026-21009 [MEDIUM] CWE-754 CVE-2026-21009: Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.
nvd
CVE-2026-21021P4MEDIUMCVSS 6.8v16.02026-05-13
CVE-2026-21021 [MEDIUM] CVE-2026-21021: Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to l Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.
nvd
CVE-2024-20832P4MEDIUMCVSS 6.7v11.0v12.0+2 more2024-03-05
CVE-2024-20832 [MEDIUM] CWE-787 CVE-2024-20832: Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.
nvd
CVE-2025-20905P4MEDIUMCVSS 6.7v12.0v13.0+1 more2025-02-04
CVE-2025-20905 [MEDIUM] CWE-125 CVE-2025-20905: Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privi Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.
nvd
CVE-2025-20983P4MEDIUMCVSS 6.7v14.0v15.02025-07-08
CVE-2025-20983 [MEDIUM] CWE-787 CVE-2025-20983: Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 al Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2025-20982P4MEDIUMCVSS 6.7v14.0v15.02025-07-08
CVE-2025-20982 [MEDIUM] CWE-787 CVE-2025-20982: Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 all Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2024-20815P4MEDIUMCVSS 6.5v11.0v12.0+2 more2024-02-06
CVE-2024-20815 [MEDIUM] CWE-287 CVE-2024-20815: Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Fe Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
nvd
CVE-2024-20816P4MEDIUMCVSS 6.5v11.0v12.0+2 more2024-02-06
CVE-2024-20816 [MEDIUM] CWE-287 CVE-2024-20816: Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR F Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
nvd
CVE-2026-21008P4MEDIUMCVSS 6.5v14.0v15.0+1 more2026-04-13
CVE-2026-21008 [MEDIUM] CVE-2026-21008: Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacke Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.
nvd
CVE-2023-21479P4MEDIUMCVSS 5.3v13.02025-09-03
CVE-2023-21479 [MEDIUM] CVE-2023-21479: Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01 Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.
nvd
CVE-2025-20944P4HIGHCVSS 7.1v13.0v14.0+1 more2025-04-08
CVE-2025-20944 [HIGH] CWE-125 CVE-2025-20944: Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows loca Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.
nvd
CVE-2023-21490P4HIGHCVSS 7.1v11.0v12.0+1 more2023-05-04
CVE-2023-21490 [HIGH] CWE-284 CVE-2023-21490: Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker t Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.
nvd
CVE-2025-21032P4MEDIUMCVSS 6.8v14.0v15.02025-09-03
CVE-2025-21032 [MEDIUM] CVE-2025-21032: Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.
nvd
CVE-2025-20993P4MEDIUMCVSS 6.8v13.0v14.0+1 more2025-06-04
CVE-2025-20993 [MEDIUM] CWE-787 CVE-2025-20993: Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2024-20861P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-05-07
CVE-2024-20861 [MEDIUM] CWE-416 CVE-2024-20861: Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged a Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause memory corruption.
nvd
CVE-2024-20842P4MEDIUMCVSS 6.7v12.0v13.0+1 more2024-04-02
CVE-2024-20842 [MEDIUM] CWE-787 CVE-2024-20842: Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2025-20904P4MEDIUMCVSS 6.7v12.0v13.0+1 more2025-02-04
CVE-2025-20904 [MEDIUM] CWE-787 CVE-2025-20904: Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged att Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.
nvd
Samsung Android vulnerabilities | cvebase