Samsung Android vulnerabilities
465 known vulnerabilities affecting samsung/android.
Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66
Vulnerabilities
Page 2 of 24
CVE-2024-34669P3HIGHCVSS 8.8v12.0v13.0+1 more2024-10-08
CVE-2024-34669 [HIGH] CWE-787 CVE-2024-34669: Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 all
Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34668P3HIGHCVSS 8.8v12.0v13.0+1 more2024-10-08
CVE-2024-34668 [HIGH] CWE-787 CVE-2024-34668: Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allo
Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34665P3HIGHCVSS 8.8v12.0v13.0+1 more2024-10-08
CVE-2024-34665 [HIGH] CWE-787 CVE-2024-34665: Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allo
Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34666P3HIGHCVSS 8.8v12.0v13.0+1 more2024-10-08
CVE-2024-34666 [HIGH] CWE-787 CVE-2024-34666: Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-
Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34667P3HIGHCVSS 8.8v12.0v13.0+1 more2024-10-08
CVE-2024-34667 [HIGH] CWE-787 CVE-2024-34667: Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allo
Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-21075P3HIGHCVSS 7.5v13.0v14.0+2 more2025-11-05
CVE-2025-21075 [HIGH] CWE-787 CVE-2025-21075: Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attacker
Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.
nvd
CVE-2025-58478P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-02
CVE-2025-58478 [HIGH] CWE-787 CVE-2025-58478: Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attacker
Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
nvd
CVE-2026-20990P3HIGHCVSS 8.1v14.0v15.0+1 more2026-03-16
CVE-2026-20990 [HIGH] CVE-2026-20990: Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 a
Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege.
nvd
CVE-2023-21459P3CRITICALCVSS 9.8v11.0v12.0+1 more2023-03-16
CVE-2023-21459 [CRITICAL] CWE-416 CVE-2023-21459: Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cau
Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.
nvd
CVE-2023-30708P3HIGHCVSS 7.5v11.0v12.0+1 more2023-09-06
CVE-2023-30708 [HIGH] CWE-287 CVE-2023-30708: Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Cap
Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.
nvd
CVE-2025-21055P3HIGHCVSS 7.5v13.0v14.0+2 more2025-10-10
CVE-2025-21055 [HIGH] CWE-125 CVE-2025-21055: Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote
Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.
nvd
CVE-2025-58480P3HIGHCVSS 7.5v13.0v14.0+2 more2025-12-02
CVE-2025-58480 [HIGH] CWE-787 CVE-2025-58480: Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote a
Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
nvd
CVE-2024-20890P3HIGHCVSS 8.8v12.0v13.0+1 more2024-07-02
CVE-2024-20890 [HIGH] CWE-287 CVE-2024-20890: Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigge
Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.
nvd
CVE-2023-21475P3HIGHCVSS 7.8v11.0v12.0+1 more2025-09-03
CVE-2023-21475 [HIGH] CWE-787 CVE-2023-21475: Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 a
Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.
nvd
CVE-2023-21476P3HIGHCVSS 7.8v11.0v12.0+1 more2025-09-03
CVE-2023-21476 [HIGH] CWE-787 CVE-2023-21476: Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 a
Out-of-bounds Write vulnerability in libaudiosaplus_sec.so library prior to SMR Apr-2023 Release 1 allows local attacker to execute arbitrary code.
nvd
CVE-2023-42532P3HIGHCVSS 7.5v11.0v12.0+1 more2023-11-07
CVE-2023-42532 [HIGH] CWE-295 CVE-2023-42532: Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker t
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.
nvd
CVE-2023-42560P3HIGHCVSS 7.8≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42560 [HIGH] CWE-787 CVE-2023-42560: Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Releas
Heap out-of-bounds write vulnerability in dec_mono_audb of libsavsac.so prior to SMR Dec-2023 Release 1 allows an attacker to execute arbitrary code.
nvd
CVE-2023-42558P3HIGHCVSS 7.8v13.02023-12-05
CVE-2023-42558 [HIGH] CWE-787 CVE-2023-42558: Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to
Out of bounds write vulnerability in HDCP in HAL prior to SMR Dec-2023 Release 1 allows attacker to perform code execution.
nvd
CVE-2023-21420P3HIGHCVSS 7.8v10.0v11.02023-02-09
CVE-2023-21420 [HIGH] CWE-134 CVE-2023-21420: Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release
Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.
nvd
CVE-2026-20971P3HIGHCVSS 7.8v13.0v14.0+2 more2026-01-09
CVE-2026-20971 [HIGH] CWE-416 CVE-2026-20971: Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially
Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code.
nvd