cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 13 of 24
CVE-2024-34655P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34655 [MEDIUM] CVE-2024-34655: Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.
nvd
CVE-2025-20952P4MEDIUMCVSS 5.5v15.02025-04-09
CVE-2025-20952 [MEDIUM] CVE-2025-20952: Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to acc Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.
nvd
CVE-2023-21477P4MEDIUMCVSS 5.5v11.0v12.0+1 more2025-09-03
CVE-2023-21477 [MEDIUM] CWE-125 CVE-2023-21477: Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.
nvd
CVE-2024-20875P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-06-04
CVE-2024-20875 [MEDIUM] CVE-2024-20875: Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows l Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files.
nvd
CVE-2023-30706P4MEDIUMCVSS 4.9v11.0v12.0+1 more2023-09-06
CVE-2023-30706 [MEDIUM] CVE-2023-30706: Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read a Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read arbitrary file with system privilege.
nvd
CVE-2025-20981P4MEDIUMCVSS 6.2v13.0v14.0+1 more2025-06-04
CVE-2025-20981 [MEDIUM] CVE-2025-20981: Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to ac Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2024-20873P4MEDIUMCVSS 6.0v14.02024-06-04
CVE-2024-20873 [MEDIUM] CWE-787 CVE-2024-20873: Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows loc Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2026-20969P4MEDIUMCVSS 5.5v13.0v14.0+2 more2026-01-09
CVE-2026-20969 [MEDIUM] CVE-2026-20969: Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to ac Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20889P4MEDIUMCVSS 5.5v12.0v13.0+1 more2025-02-04
CVE-2025-20889 [MEDIUM] CWE-787 CVE-2025-20889: Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20891P4MEDIUMCVSS 5.5v12.0v13.0+1 more2025-02-04
CVE-2025-20891 [MEDIUM] CWE-125 CVE-2025-20891: Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20887P4MEDIUMCVSS 5.5v12.0v13.0+1 more2025-02-04
CVE-2025-20887 [MEDIUM] CWE-125 CVE-2025-20887: Out-of-bounds read in accessing table used for svp8t in libsthmbc.so prior to SMR Jan-2025 Release 1 Out-of-bounds read in accessing table used for svp8t in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34647P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34647 [MEDIUM] CVE-2024-34647: Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.
nvd
CVE-2024-34651P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34651 [MEDIUM] CWE-863 CVE-2024-34651: Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
nvd
CVE-2023-30701P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-08-10
CVE-2023-30701 [MEDIUM] CVE-2023-30701: PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.
nvd
CVE-2023-21478P4MEDIUMCVSS 5.5v11.0v12.0+1 more2025-09-03
CVE-2023-21478 [MEDIUM] CVE-2023-21478: Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows lo Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.
nvd
CVE-2026-21025P4MEDIUMCVSS 5.5v14.0v15.0+1 more2026-06-05
CVE-2026-21025 [MEDIUM] CVE-2026-21025: Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers t Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2026-21016P4MEDIUMCVSS 5.5v14.0v15.0+1 more2026-05-13
CVE-2026-21016 [MEDIUM] CVE-2026-21016: Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attac Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2026-21015P4MEDIUMCVSS 5.5v14.0v15.0+1 more2026-05-13
CVE-2026-21015 [MEDIUM] CWE-276 CVE-2026-21015: Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.
nvd
CVE-2025-20892P4MEDIUMCVSS 5.9v13.0v14.02025-02-04
CVE-2025-20892 [MEDIUM] CVE-2025-20892: Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. User interaction is required for triggering this vulnerability.
nvd
CVE-2023-42564P4MEDIUMCVSS 5.5≥ 12.0, < 14.0v14.02023-12-05
CVE-2023-42564 [MEDIUM] CVE-2023-42564: Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to sen Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
nvd