cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 18 of 24
CVE-2024-20830P4MEDIUMCVSS 5.3v11.0v12.0+2 more2024-03-05
CVE-2024-20830 [MEDIUM] CWE-276 CVE-2024-20830: Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to co Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.
nvd
CVE-2023-42559P4MEDIUMCVSS 5.2≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42559 [MEDIUM] CWE-755 CVE-2023-42559: Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Kno Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.
nvd
CVE-2025-20989P4MEDIUMCVSS 5.2v13.0v14.0+1 more2025-06-04
CVE-2025-20989 [MEDIUM] CVE-2025-20989: Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged att Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key.
nvd
CVE-2026-20974P4MEDIUMCVSS 4.6v13.0v14.0+2 more2026-01-09
CVE-2026-20974 [MEDIUM] CVE-2026-20974: Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 al Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
nvd
CVE-2023-42556P4MEDIUMCVSS 5.5≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42556 [MEDIUM] CVE-2023-42556: Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get Improper usage of implicit intent in Contacts prior to SMR Dec-2023 Release 1 allows attacker to get sensitive information.
nvd
CVE-2023-21435P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-02-09
CVE-2023-21435 [MEDIUM] CWE-200 CVE-2023-21435: Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 al Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.
nvd
CVE-2023-21440P4MEDIUMCVSS 5.5v13.02023-02-09
CVE-2023-21440 [MEDIUM] CWE-285 CVE-2023-21440: Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows Improper access control vulnerability in WindowManagerService prior to SMR Feb-2023 Release 1 allows attackers to take a screen capture.
nvd
CVE-2023-30671P4MEDIUMCVSS 5.5v12.0v13.02023-07-06
CVE-2023-30671 [MEDIUM] CVE-2023-30671: Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local att Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.
nvd
CVE-2024-34644P4MEDIUMCVSS 5.5v14.02024-09-04
CVE-2024-34644 [MEDIUM] CVE-2024-34644: Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allow Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.
nvd
CVE-2026-20977P4MEDIUMCVSS 5.5v14.0v15.0+1 more2026-02-04
CVE-2026-20977 [MEDIUM] CVE-2026-20977: Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.
nvd
CVE-2025-21044P4MEDIUMCVSS 4.4v13.0v14.0+2 more2025-10-10
CVE-2025-21044 [MEDIUM] CWE-787 CVE-2025-21044: Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2024-20889P4MEDIUMCVSS 4.3v12.0v13.0+1 more2024-07-02
CVE-2024-20889 [MEDIUM] CWE-287 CVE-2024-20889: Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair wit Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.
nvd
CVE-2025-21010P4MEDIUMCVSS 6.0v13.0v14.0+2 more2025-08-06
CVE-2025-21010 [MEDIUM] CVE-2025-21010: Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privile Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.
nvd
CVE-2024-34602P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-07-08
CVE-2024-34602 [MEDIUM] CVE-2024-34602: Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.
nvd
CVE-2023-21461P4MEDIUMCVSS 5.5v11.0v12.0+1 more2023-03-16
CVE-2023-21461 [MEDIUM] CWE-285 CVE-2023-21461: Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-202 Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
nvd
CVE-2025-20893P4MEDIUMCVSS 5.1v14.02025-02-04
CVE-2025-20893 [MEDIUM] CVE-2025-20893: Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attacker Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications.
nvd
CVE-2025-21071P4MEDIUMCVSS 4.4v13.0v14.0+2 more2025-11-05
CVE-2025-21071 [MEDIUM] CWE-787 CVE-2025-21071: Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allow Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2024-20856P4MEDIUMCVSS 4.3v14.02024-05-07
CVE-2024-20856 [MEDIUM] CWE-287 CVE-2024-20856: Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physic Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.
nvd
CVE-2024-34673P4MEDIUMCVSS 5.5v12.0v13.0+1 more2024-11-06
CVE-2024-34673 [MEDIUM] CVE-2024-34673: Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attac Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.
nvd
CVE-2025-21008P4MEDIUMCVSS 5.5fixed in 15.02025-07-08
CVE-2025-21008 [MEDIUM] CWE-125 CVE-2025-21008: Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attacke Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
nvd
Samsung Android vulnerabilities | cvebase