Samsung Android vulnerabilities

448 known vulnerabilities affecting samsung/android.

Total CVEs
448
CISA KEV
12
actively exploited
Public exploits
0
Exploited in wild
10
Severity breakdown
CRITICAL9HIGH160MEDIUM218LOW61

Vulnerabilities

Page 12 of 23
CVE-2024-20897MEDIUMCVSS 5.5v12.0v13.0+1 more2024-07-02
CVE-2024-20897 [MEDIUM] CVE-2024-20897: Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2 Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
nvd
CVE-2024-34590MEDIUMCVSS 4.3v12.0v13.0+1 more2024-07-02
CVE-2024-34590 [MEDIUM] CVE-2024-34590: Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Ju Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-20900LOWCVSS 3.3v12.0v13.0+1 more2024-07-02
CVE-2024-20900 [LOW] CWE-287 CVE-2024-20900: Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
nvd
CVE-2024-34586LOWCVSS 3.3v12.0v13.0+1 more2024-07-02
CVE-2024-34586 [LOW] CVE-2024-34586: Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local att Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.
nvd
CVE-2024-34583LOWCVSS 3.3v12.0v13.0+1 more2024-07-02
CVE-2024-34583 [LOW] CVE-2024-34583: Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.
nvd
CVE-2024-20879HIGHCVSS 7.1v12.0v13.0+1 more2024-06-04
CVE-2024-20879 [HIGH] CVE-2024-20879: Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows loca Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2024-20884HIGHCVSS 7.8v14.02024-06-04
CVE-2024-20884 [HIGH] CVE-2024-20884: Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prio Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.
nvd
CVE-2024-20883HIGHCVSS 7.8v14.02024-06-04
CVE-2024-20883 [HIGH] CVE-2024-20883: Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.
nvd
CVE-2024-20876HIGHCVSS 7.8v12.0v13.0+1 more2024-06-04
CVE-2024-20876 [HIGH] CVE-2024-20876: Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local atta Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.
nvd
CVE-2024-20874HIGHCVSS 7.8v13.0v14.02024-06-04
CVE-2024-20874 [HIGH] CVE-2024-20874: Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2024-20878HIGHCVSS 7.8v12.0v13.0+1 more2024-06-04
CVE-2024-20878 [HIGH] CWE-787 CVE-2024-20878: Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2024-20877HIGHCVSS 7.8v12.0v13.0+1 more2024-06-04
CVE-2024-20877 [HIGH] CWE-787 CVE-2024-20877: Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2024-20875MEDIUMCVSS 5.5v12.0v13.0+1 more2024-06-04
CVE-2024-20875 [MEDIUM] CVE-2024-20875: Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows l Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files.
nvd
CVE-2024-20882MEDIUMCVSS 4.6v12.0v13.0+1 more2024-06-04
CVE-2024-20882 [MEDIUM] CWE-125 CVE-2024-20882: Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical atta Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.
nvd
CVE-2024-20880MEDIUMCVSS 6.8v12.0v13.0+1 more2024-06-04
CVE-2024-20880 [MEDIUM] CWE-787 CVE-2024-20880: Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physi Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.
nvd
CVE-2024-20873MEDIUMCVSS 6.0v14.02024-06-04
CVE-2024-20873 [MEDIUM] CWE-787 CVE-2024-20873: Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows loc Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2024-20881MEDIUMCVSS 6.7v12.0v13.02024-06-04
CVE-2024-20881 [MEDIUM] CVE-2024-20881: Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local privileged attackers lead to potential arbitrary code execution.
nvd
CVE-2024-20885LOWCVSS 3.3v14.02024-06-04
CVE-2024-20885 [LOW] CVE-2024-20885: Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.
nvd
CVE-2024-20864MEDIUMCVSS 5.5v14.02024-05-07
CVE-2024-20864 [MEDIUM] CVE-2024-20864: Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows lo Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.
nvd
CVE-2024-20862MEDIUMCVSS 6.7v11.0v12.0+2 more2024-05-07
CVE-2024-20862 [MEDIUM] CWE-787 CVE-2024-20862: Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.
nvd