Samsung Android vulnerabilities
465 known vulnerabilities affecting samsung/android.
Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66
Vulnerabilities
Page 12 of 24
CVE-2025-20885P4MEDIUMCVSS 6.7v12.0v13.0+1 more2025-02-04
CVE-2025-20885 [MEDIUM] CWE-787 CVE-2025-20885: Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged atta
Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memory corruption.
nvd
CVE-2025-20987P4MEDIUMCVSS 6.7v13.0v14.0+1 more2025-06-04
CVE-2025-20987 [MEDIUM] CVE-2025-20987: Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privile
Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a auth_token.
nvd
CVE-2024-34589P4MEDIUMCVSS 6.5v12.0v13.0+1 more2024-07-02
CVE-2024-34589 [MEDIUM] CVE-2024-34589: Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 all
Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20908P4MEDIUMCVSS 6.5v14.0v15.02025-03-06
CVE-2025-20908 [MEDIUM] CVE-2025-20908: Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent atta
Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.
nvd
CVE-2026-20978P4MEDIUMCVSS 6.1v13.0v14.0+2 more2026-02-04
CVE-2026-20978 [MEDIUM] CVE-2026-20978: Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to
Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
nvd
CVE-2023-21456P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-03-16
CVE-2023-21456 [MEDIUM] CWE-22 CVE-2023-21456: Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacke
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
nvd
CVE-2024-20804P4MEDIUMCVSS 5.5v11.0v12.02024-01-04
CVE-2024-20804 [MEDIUM] CWE-22 CVE-2024-20804: Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Andro
Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
nvd
CVE-2024-20805P4MEDIUMCVSS 5.5v11.0v12.02024-01-04
CVE-2024-20805 [MEDIUM] CWE-22 CVE-2024-20805: Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
nvd
CVE-2024-20820P4HIGHCVSS 7.1v11.0v12.0+1 more2024-02-06
CVE-2024-20820 [HIGH] CWE-125 CVE-2024-20820: Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged atta
Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.
nvd
CVE-2024-34638P4HIGHCVSS 7.1v12.0v13.0+1 more2024-09-04
CVE-2024-34638 [HIGH] CWE-755 CVE-2024-34638: Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows lo
Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.
nvd
CVE-2023-21473P4MEDIUMCVSS 6.8v11.0v12.0+1 more2025-09-03
CVE-2023-21473 [MEDIUM] CWE-20 CVE-2023-21473: Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.
nvd
CVE-2023-21472P4MEDIUMCVSS 6.8v11.0v12.0+1 more2025-09-03
CVE-2023-21472 [MEDIUM] CWE-20 CVE-2023-21472: Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.
nvd
CVE-2025-21047P4MEDIUMCVSS 6.8v14.0v15.0+1 more2025-10-10
CVE-2025-21047 [MEDIUM] CVE-2025-21047: Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to us
Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.
nvd
CVE-2024-34588P4MEDIUMCVSS 6.5v12.0v13.0+1 more2024-07-02
CVE-2024-34588 [MEDIUM] CVE-2024-34588: Improper input validation혻in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 all
Improper input validation혻in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-20833P4MEDIUMCVSS 6.4v11.0v12.0+2 more2024-03-05
CVE-2024-20833 [MEDIUM] CWE-416 CVE-2024-20833: Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race cond
Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.
nvd
CVE-2023-30720P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-09-06
CVE-2023-30720 [MEDIUM] CVE-2023-30720: PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attack
PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.
nvd
CVE-2023-21513P4MEDIUMCVSS 6.8v11.0v12.0+1 more2023-06-28
CVE-2023-21513 [MEDIUM] CWE-269 CVE-2023-21513: Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physic
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
nvd
CVE-2023-30709P4MEDIUMCVSS 6.7v11.0v12.0+1 more2023-09-06
CVE-2023-30709 [MEDIUM] CVE-2023-30709: Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers lau
Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.
nvd
CVE-2023-21427P4MEDIUMCVSS 6.5v11.0v12.0+1 more2023-02-09
CVE-2023-21427 [MEDIUM] CWE-284 CVE-2023-21427: Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker
Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition.
nvd
CVE-2023-42534P4MEDIUMCVSS 5.5v12.0v13.02023-11-07
CVE-2023-42534 [MEDIUM] CWE-552 CVE-2023-42534: Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows lo
Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.
nvd