cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 15 of 24
CVE-2023-21496P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-05-04
CVE-2023-21496 [MEDIUM] CWE-489 CVE-2023-21496: Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows att Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.
nvd
CVE-2023-30661P4MEDIUMCVSS 5.5v12.0v13.02023-07-06
CVE-2023-30661 [MEDIUM] CVE-2023-30661: Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SM Exposure of Sensitive Information vulnerability in getChipInfos in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
nvd
CVE-2023-30662P4MEDIUMCVSS 5.5v12.0v13.02023-07-06
CVE-2023-30662 [MEDIUM] CVE-2023-30662: Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Exposure of Sensitive Information vulnerability in getChipIds in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
nvd
CVE-2023-30660P4MEDIUMCVSS 5.5v12.0v13.02023-07-06
CVE-2023-30660 [MEDIUM] CVE-2023-30660: Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior t Exposure of Sensitive Information vulnerability in getDefaultChipId in UwbAospAdapterService prior to SMR Jul-2023 Release 1 allows local attackers to access the UWB chipset Identifier.
nvd
CVE-2023-21500P4MEDIUMCVSS 5.5v13.02023-05-04
CVE-2023-21500 [MEDIUM] CWE-415 CVE-2023-21500: Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 R Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
nvd
CVE-2023-21453P4MEDIUMCVSS 5.5v13.02023-03-16
CVE-2023-21453 [MEDIUM] CWE-20 CVE-2023-21453: Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local a Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
nvd
CVE-2025-20947P4MEDIUMCVSS 5.5v13.0v14.0+1 more2025-04-08
CVE-2025-20947 [MEDIUM] CVE-2025-20947: Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-20859P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-05-07
CVE-2024-20859 [MEDIUM] CVE-2024-20859: Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.
nvd
CVE-2024-20858P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-05-07
CVE-2024-20858 [MEDIUM] CVE-2024-20858: Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.
nvd
CVE-2024-20857P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-05-07
CVE-2024-20857 [MEDIUM] CVE-2024-20857: Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Improper access control vulnerability in startListening of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.
nvd
CVE-2024-34594P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-07-02
CVE-2024-34594 [MEDIUM] CVE-2024-34594: Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local a Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.
nvd
CVE-2023-21493P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-05-04
CVE-2023-21493 [MEDIUM] CWE-284 CVE-2023-21493: Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.
nvd
CVE-2023-21495P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-05-04
CVE-2023-21495 [MEDIUM] CWE-284 CVE-2023-21495: Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 all Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
nvd
CVE-2023-21422P4MEDIUMCVSS 5.5v11.0v12.02023-02-09
CVE-2023-21422 [MEDIUM] CWE-285 CVE-2023-21422: Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Rele Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
nvd
CVE-2024-20896P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-07-02
CVE-2024-20896 [MEDIUM] CVE-2024-20896: Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Re Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
nvd
CVE-2023-30642P4MEDIUMCVSS 5.5v12.0v13.02023-07-06
CVE-2023-30642 [MEDIUM] CWE-269 CVE-2023-30642: Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 Improper privilege management vulnerability in Galaxy Themes Service prior to SMR Jul-2023 Release 1 allows local attackers to call privilege function.
nvd
CVE-2024-34637P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34637 [MEDIUM] CVE-2024-34637: Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and S Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.
nvd
CVE-2024-20895P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-07-02
CVE-2024-20895 [MEDIUM] CVE-2024-20895: Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to byp Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.
nvd
CVE-2023-30716P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-09-06
CVE-2023-30716 [MEDIUM] CVE-2023-30716: Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers t Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to trigger certain commands.
nvd
CVE-2024-34609P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-08-07
CVE-2024-34609 [MEDIUM] CVE-2024-34609: Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers t Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
nvd