Samsung Android vulnerabilities
448 known vulnerabilities affecting samsung/android.
Total CVEs
448
CISA KEV
12
actively exploited
Public exploits
0
Exploited in wild
10
Severity breakdown
CRITICAL9HIGH160MEDIUM218LOW61
Vulnerabilities
Page 17 of 23
CVE-2023-30721MEDIUMCVSS 4.4v11.0v12.0+1 more2023-09-06
CVE-2023-30721 [MEDIUM] CWE-532 CVE-2023-30721: Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Rele
Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.
nvd
CVE-2023-30709MEDIUMCVSS 6.7v11.0v12.0+1 more2023-09-06
CVE-2023-30709 [MEDIUM] CVE-2023-30709: Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers lau
Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.
nvd
CVE-2023-30714MEDIUMCVSS 4.6v11.0v12.0+1 more2023-09-06
CVE-2023-30714 [MEDIUM] CVE-2023-30714: Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-
Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.
nvd
CVE-2023-30720MEDIUMCVSS 5.5v11.0v12.0+1 more2023-09-06
CVE-2023-30720 [MEDIUM] CVE-2023-30720: PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attack
PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.
nvd
CVE-2023-30706MEDIUMCVSS 4.9v11.0v12.0+1 more2023-09-06
CVE-2023-30706 [MEDIUM] CVE-2023-30706: Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read a
Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read arbitrary file with system privilege.
nvd
CVE-2023-30713MEDIUMCVSS 5.5v11.0v12.0+1 more2023-09-06
CVE-2023-30713 [MEDIUM] CWE-269 CVE-2023-30713: Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-20
Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.
nvd
CVE-2023-30716MEDIUMCVSS 5.5v11.0v12.0+1 more2023-09-06
CVE-2023-30716 [MEDIUM] CVE-2023-30716: Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers t
Improper access control vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to trigger certain commands.
nvd
CVE-2023-30715LOWCVSS 3.3v11.0v12.0+1 more2023-09-06
CVE-2023-30715 [LOW] CVE-2023-30715: Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to
Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.
nvd
CVE-2023-30717LOWCVSS 3.3v11.0v12.0+1 more2023-09-06
CVE-2023-30717 [LOW] CVE-2023-30717: Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows atta
Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to get unresettable identifiers.
nvd
CVE-2023-30711LOWCVSS 3.3v11.0v12.0+1 more2023-09-06
CVE-2023-30711 [LOW] CVE-2023-30711: Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to ins
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
nvd
CVE-2023-30718LOWCVSS 3.3v11.0v12.0+1 more2023-09-06
CVE-2023-30718 [LOW] CVE-2023-30718: Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity
Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.
nvd
CVE-2023-30719LOWCVSS 3.3v11.0v12.0+1 more2023-09-06
CVE-2023-30719 [LOW] CVE-2023-30719: Exposure of Sensitive Information vulnerability in InboundSmsHandler prior to SMR Sep-2023 Release 1
Exposure of Sensitive Information vulnerability in InboundSmsHandler prior to SMR Sep-2023 Release 1 allows local attackers to access certain message data.
nvd
CVE-2023-30699CRITICALCVSS 9.8v11.0v12.0+1 more2023-08-10
CVE-2023-30699 [CRITICAL] CWE-787 CVE-2023-30699: Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023
Out-of-bounds write vulnerability in parser_hvcC function of libsimba library prior to SMR Aug-2023 Release 1 allows code execution by remote attackers.
nvd
CVE-2023-30693HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30693 [HIGH] CWE-787 CVE-2023-30693: Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Rele
Out-of-bounds Write in DoOemFactorySendFactoryBypassCommand of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
nvd
CVE-2023-30680HIGHCVSS 7.8v12.0v13.02023-08-10
CVE-2023-30680 [HIGH] CWE-269 CVE-2023-30680: Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows code execution with privilege.
nvd
CVE-2023-30696HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30696 [HIGH] CWE-787 CVE-2023-30696: An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 all
An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
nvd
CVE-2023-30689HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30689 [HIGH] CWE-787 CVE-2023-30689: Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Relea
Out-of-bounds Write in BuildOemEmbmsGetSigStrengthResponse of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
nvd
CVE-2023-30694HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30694 [HIGH] CWE-787 CVE-2023-30694: Out-of-bounds Write in IpcTxPcscTransmitApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows lo
Out-of-bounds Write in IpcTxPcscTransmitApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
nvd
CVE-2023-30691HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30691 [HIGH] CWE-266 CVE-2023-30691: Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to pri
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.
nvd
CVE-2023-30687HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30687 [HIGH] CWE-787 CVE-2023-30687: Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacke
Out-of-bounds Write in RmtUimApdu of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
nvd