Samsung Android vulnerabilities
448 known vulnerabilities affecting samsung/android.
Total CVEs
448
CISA KEV
12
actively exploited
Public exploits
0
Exploited in wild
10
Severity breakdown
CRITICAL9HIGH160MEDIUM218LOW61
Vulnerabilities
Page 15 of 23
CVE-2024-20803MEDIUMCVSS 6.5v11.0v12.0+2 more2024-01-04
CVE-2024-20803 [MEDIUM] CWE-287 CVE-2024-20803: Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 a
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
nvd
CVE-2024-20804MEDIUMCVSS 5.5v11.0v12.02024-01-04
CVE-2024-20804 [MEDIUM] CWE-22 CVE-2024-20804: Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Andro
Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
nvd
CVE-2023-42562HIGHCVSS 7.8≥ 12.0, < 14.0v14.02023-12-05
CVE-2023-42562 [HIGH] CWE-190 CVE-2023-42562: Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.c
Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
nvd
CVE-2023-42560HIGHCVSS 7.8≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42560 [HIGH] CWE-787 CVE-2023-42560: Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Releas
Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.
nvd
CVE-2023-42563HIGHCVSS 7.8≥ 12.0, < 14.0v14.02023-12-05
CVE-2023-42563 [HIGH] CWE-190 CVE-2023-42563: Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsun
Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
nvd
CVE-2023-42558HIGHCVSS 7.8v13.02023-12-05
CVE-2023-42558 [HIGH] CWE-787 CVE-2023-42558: Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to
Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.
nvd
CVE-2023-42566HIGHCVSS 7.8≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42566 [HIGH] CWE-787 CVE-2023-42566: Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers
Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-42567HIGHCVSS 7.8v14.02023-12-05
CVE-2023-42567 [HIGH] CWE-787 CVE-2023-42567: Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buf
Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.
nvd
CVE-2023-42556MEDIUMCVSS 5.5≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42556 [MEDIUM] CVE-2023-42556: Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get
Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.
nvd
CVE-2023-42557MEDIUMCVSS 6.7≥ 12.0, < 14.0v14.02023-12-05
CVE-2023-42557 [MEDIUM] CWE-787 CVE-2023-42557: Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system at
Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.
nvd
CVE-2023-42559MEDIUMCVSS 5.2≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42559 [MEDIUM] CWE-755 CVE-2023-42559: Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Kno
Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.
nvd
CVE-2023-42568MEDIUMCVSS 4.4≥ 12.0, < 13.0v13.02023-12-05
CVE-2023-42568 [MEDIUM] CVE-2023-42568: Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local
Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
nvd
CVE-2023-42565MEDIUMCVSS 6.7≥ 13.0, < 14.0v14.02023-12-05
CVE-2023-42565 [MEDIUM] CVE-2023-42565: Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local a
Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.
nvd
CVE-2023-42561MEDIUMCVSS 6.8≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42561 [MEDIUM] CWE-787 CVE-2023-42561: Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physic
Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.
nvd
CVE-2023-42564MEDIUMCVSS 5.5≥ 12.0, < 14.0v14.02023-12-05
CVE-2023-42564 [MEDIUM] CVE-2023-42564: Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to sen
Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
nvd
CVE-2023-42570LOWCVSS 3.3≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42570 [LOW] CVE-2023-42570: Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 al
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.
nvd
CVE-2023-42569LOWCVSS 3.3≥ 11.0, < 13.0v13.02023-12-05
CVE-2023-42569 [LOW] CWE-863 CVE-2023-42569: Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows
Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.
nvd
CVE-2023-42531HIGHCVSS 7.1v11.0v12.0+1 more2023-11-07
CVE-2023-42531 [HIGH] CWE-287 CVE-2023-42531: Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local a
Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.
nvd
CVE-2023-42529HIGHCVSS 7.8v11.0v12.0+1 more2023-11-07
CVE-2023-42529 [HIGH] CWE-787 CVE-2023-42529: Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker
Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-42532HIGHCVSS 7.5v11.0v12.0+1 more2023-11-07
CVE-2023-42532 [HIGH] CWE-295 CVE-2023-42532: Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker t
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.
nvd