Samsung Android vulnerabilities

448 known vulnerabilities affecting samsung/android.

Total CVEs
448
CISA KEV
12
actively exploited
Public exploits
0
Exploited in wild
10
Severity breakdown
CRITICAL9HIGH160MEDIUM218LOW61

Vulnerabilities

Page 18 of 23
CVE-2023-30697HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30697 [HIGH] CWE-787 CVE-2023-30697: An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Releas An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
nvd
CVE-2023-30681HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30681 [HIGH] CWE-787 CVE-2023-30681: An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SM An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
nvd
CVE-2023-30686HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30686 [HIGH] CWE-787 CVE-2023-30686: Out-of-bounds Write in ReqDataRaw of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacke Out-of-bounds Write in ReqDataRaw of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
nvd
CVE-2023-30688HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30688 [HIGH] CWE-787 CVE-2023-30688: Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local Out-of-bounds Write in MakeUiccAuthForOem of libsec-ril prior to SMR Aug-2023 Release 1 allows local attacker to execute arbitrary code.
nvd
CVE-2023-30679HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30679 [HIGH] CVE-2023-30679: Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to e Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-30701MEDIUMCVSS 5.5v11.0v12.0+1 more2023-08-10
CVE-2023-30701 [MEDIUM] CVE-2023-30701: PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.
nvd
CVE-2023-30698MEDIUMCVSS 5.5v13.02023-08-10
CVE-2023-30698 [MEDIUM] CVE-2023-30698: Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local at Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.
nvd
CVE-2023-30654MEDIUMCVSS 5.5v11.0v12.0+1 more2023-08-10
CVE-2023-30654 [MEDIUM] CVE-2023-30654: Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows loc Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to update fake location.
nvd
CVE-2023-30682LOWCVSS 3.3v13.02023-08-10
CVE-2023-30682 [LOW] CVE-2023-30682: Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call si Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.
nvd
CVE-2023-30683LOWCVSS 3.3v13.02023-08-10
CVE-2023-30683 [LOW] CVE-2023-30683: Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call en Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.
nvd
CVE-2023-30684LOWCVSS 3.3v13.02023-08-10
CVE-2023-30684 [LOW] CVE-2023-30684: Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.
nvd
CVE-2023-30700LOWCVSS 3.3v11.0v12.0+1 more2023-08-10
CVE-2023-30700 [LOW] CVE-2023-30700: PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Rel PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.
nvd
CVE-2023-30685LOWCVSS 3.3v11.0v12.0+1 more2023-08-10
CVE-2023-30685 [LOW] CVE-2023-30685: Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakc Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
nvd
CVE-2023-30668HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30668 [HIGH] CWE-787 CVE-2023-30668: Out-of-bounds Write in BuildOemSecureSimLockResponse of libsec-ril prior to SMR Jul-2023 Release 1 a Out-of-bounds Write in BuildOemSecureSimLockResponse of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
nvd
CVE-2023-30650HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30650 [HIGH] CWE-787 CVE-2023-30650: Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-30653HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30653 [HIGH] CWE-787 CVE-2023-30653: Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Releas Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-30647HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30647 [HIGH] CWE-787 CVE-2023-30647: Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Releas Heap out of bound write vulnerability in IpcRxUsimPhoneBookCapa of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
nvd
CVE-2023-30644HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30644 [HIGH] CWE-787 CVE-2023-30644: Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allo Stack out of bound write vulnerability in CdmaSmsParser of RILD prior to SMR Jul-2023 Release 1 allows attackers to execute arbitrary code.
nvd
CVE-2023-30669HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30669 [HIGH] CWE-787 CVE-2023-30669: Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release Out-of-bounds Write in DoOemFactorySendFactoryTestResult of libsec-ril prior to SMR Jul-2023 Release 1 allows local attacker to execute arbitrary code.
nvd
CVE-2023-30664HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30664 [HIGH] CWE-20 CVE-2023-30664: Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows l Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
nvd