cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 17 of 24
CVE-2025-21028P4MEDIUMCVSS 5.5v15.0v16.02025-09-03
CVE-2025-21028 [MEDIUM] CVE-2025-21028: Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privilege Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
nvd
CVE-2026-21026P4MEDIUMCVSS 5.5v16.02026-06-05
CVE-2026-21026 [MEDIUM] CVE-2026-21026: Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.
nvd
CVE-2026-21022P4MEDIUMCVSS 5.5v15.0v16.02026-05-13
CVE-2026-21022 [MEDIUM] CVE-2026-21022: Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows loc Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2024-34653P4MEDIUMCVSS 4.6v12.0v13.0+1 more2024-09-04
CVE-2024-34653 [MEDIUM] CWE-22 CVE-2024-34653: Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access direc Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.
nvd
CVE-2024-49411P4MEDIUMCVSS 4.6v12.0v13.0+1 more2024-12-03
CVE-2024-49411 [MEDIUM] CWE-22 CVE-2024-49411: Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
nvd
CVE-2023-42527P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-11-07
CVE-2023-42527 [MEDIUM] CWE-20 CVE-2023-42527: Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Rele Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.
nvd
CVE-2024-20814P4MEDIUMCVSS 5.5v11.0v12.0+2 more2024-02-06
CVE-2024-20814 [MEDIUM] CWE-125 CVE-2024-20814: Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.
nvd
CVE-2023-30648P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-07-06
CVE-2023-30648 [MEDIUM] CWE-787 CVE-2023-30648: Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Rel Stack out-of-bounds write vulnerability in IpcRxImeiUpdateImeiNoti of RILD priro to SMR Jul-2023 Release 1 cause a denial of service on the system.
nvd
CVE-2023-21449P4MEDIUMCVSS 5.5v11.0v12.02023-03-16
CVE-2023-21449 [MEDIUM] CWE-200 CVE-2023-21449: Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows loc Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.
nvd
CVE-2024-34643P4MEDIUMCVSS 5.5v14.02024-09-04
CVE-2024-34643 [MEDIUM] CVE-2024-34643: Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 a Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.
nvd
CVE-2023-30654P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-08-10
CVE-2023-30654 [MEDIUM] CVE-2023-30654: Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows loc Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to update fake location.
nvd
CVE-2024-20836P4MEDIUMCVSS 5.5v11.0v12.0+2 more2024-03-05
CVE-2024-20836 [MEDIUM] CWE-125 CVE-2024-20836: Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Releas Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.
nvd
CVE-2023-21437P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-02-09
CVE-2023-21437 [MEDIUM] CWE-287 CVE-2023-21437: Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows lo Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.
nvd
CVE-2023-21425P4MEDIUMCVSS 5.5v10.0v11.0+2 more2023-02-09
CVE-2023-21425 [MEDIUM] CWE-287 CVE-2023-21425: Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.
nvd
CVE-2025-20954P4MEDIUMCVSS 5.5v13.0v14.0+1 more2025-05-07
CVE-2025-20954 [MEDIUM] CVE-2025-20954: Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 a Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
nvd
CVE-2023-30713P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-09-06
CVE-2023-30713 [MEDIUM] CWE-269 CVE-2023-30713: Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-20 Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.
nvd
CVE-2024-20897P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-07-02
CVE-2024-20897 [MEDIUM] CVE-2024-20897: Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2 Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
nvd
CVE-2024-20899P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-07-02
CVE-2024-20899 [MEDIUM] CVE-2024-20899: Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2 Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
nvd
CVE-2025-21049P4MEDIUMCVSS 5.5v15.0v16.02025-10-10
CVE-2025-21049 [MEDIUM] CVE-2025-21049: Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to acc Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-21007P4MEDIUMCVSS 5.5fixed in 15.02025-07-08
CVE-2025-21007 [MEDIUM] CWE-787 CVE-2025-21007: Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows loc Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
nvd