Samsung Android vulnerabilities

448 known vulnerabilities affecting samsung/android.

Total CVEs
448
CISA KEV
12
actively exploited
Public exploits
0
Exploited in wild
10
Severity breakdown
CRITICAL9HIGH160MEDIUM218LOW61

Vulnerabilities

Page 21 of 23
CVE-2023-21493MEDIUMCVSS 5.5v11.0v12.0+1 more2023-05-04
CVE-2023-21493 [MEDIUM] CWE-284 CVE-2023-21493: Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.
nvd
CVE-2023-21492MEDIUMCVSS 4.4KEVv11.0v12.0+1 more2023-05-04
CVE-2023-21492 [MEDIUM] CWE-532 CVE-2023-21492: Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged loca Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
nvd
CVE-2023-21496MEDIUMCVSS 5.5v11.0v12.0+1 more2023-05-04
CVE-2023-21496 [MEDIUM] CWE-489 CVE-2023-21496: Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows att Active Debug Code vulnerability in ActivityManagerService prior to SMR May-2023 Release 1 allows attacker to use debug function via setting debug level.
nvd
CVE-2023-21500MEDIUMCVSS 5.5v13.02023-05-04
CVE-2023-21500 [MEDIUM] CWE-415 CVE-2023-21500: Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 R Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.
nvd
CVE-2023-21495MEDIUMCVSS 5.5v11.0v12.0+1 more2023-05-04
CVE-2023-21495 [MEDIUM] CWE-284 CVE-2023-21495: Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 all Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
nvd
CVE-2023-21486MEDIUMCVSS 4.6v11.0v12.0+1 more2023-05-04
CVE-2023-21486 [MEDIUM] CWE-926 CVE-2023-21486: Improper export of android application components vulnerability in ImagePreviewActivity in Call Sett Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
nvd
CVE-2023-21487LOWCVSS 3.3v11.0v12.0+1 more2023-05-04
CVE-2023-21487 [LOW] CWE-287 CVE-2023-21487: Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.
nvd
CVE-2023-21459CRITICALCVSS 9.8v11.0v12.0+1 more2023-03-16
CVE-2023-21459 [CRITICAL] CWE-416 CVE-2023-21459: Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cau Use after free vulnerability in decon driver prior to SMR Mar-2023 Release 1 allows attackers to cause memory access fault.
nvd
CVE-2023-21457HIGHCVSS 8.1v11.0v12.0+1 more2023-03-16
CVE-2023-21457 [HIGH] CWE-284 CVE-2023-21457: Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.
nvd
CVE-2023-21461MEDIUMCVSS 5.5v11.0v12.0+1 more2023-03-16
CVE-2023-21461 [MEDIUM] CWE-285 CVE-2023-21461: Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-202 Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
nvd
CVE-2023-21453MEDIUMCVSS 5.5v13.02023-03-16
CVE-2023-21453 [MEDIUM] CWE-20 CVE-2023-21453: Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local a Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
nvd
CVE-2023-21449MEDIUMCVSS 5.5v11.0v12.02023-03-16
CVE-2023-21449 [MEDIUM] CWE-200 CVE-2023-21449: Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows loc Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.
nvd
CVE-2023-21456MEDIUMCVSS 5.5v11.0v12.0+1 more2023-03-16
CVE-2023-21456 [MEDIUM] CWE-22 CVE-2023-21456: Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacke Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
nvd
CVE-2023-21460MEDIUMCVSS 4.4v11.0v12.0+1 more2023-03-16
CVE-2023-21460 [MEDIUM] CWE-287 CVE-2023-21460: Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
nvd
CVE-2023-21458LOWCVSS 3.3v11.0v12.0+1 more2023-03-16
CVE-2023-21458 [LOW] CWE-269 CVE-2023-21458: Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-20 Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
nvd
CVE-2023-21452LOWCVSS 3.3v11.0v12.0+1 more2023-03-16
CVE-2023-21452 [LOW] CWE-285 CVE-2023-21452: Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to ge Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
nvd
CVE-2023-21454LOWCVSS 2.4v11.0v12.0+1 more2023-03-16
CVE-2023-21454 [LOW] CWE-285 CVE-2023-21454: Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.
nvd
CVE-2023-21430HIGHCVSS 7.8v10.0v11.0+2 more2023-02-09
CVE-2023-21430 [HIGH] CWE-125 CVE-2023-21430: An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung. An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2023-21451HIGHCVSS 7.8v12.02023-02-09
CVE-2023-21451 [HIGH] CWE-20 CVE-2023-21451: A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allow A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.
nvd
CVE-2023-21420HIGHCVSS 7.8v10.0v11.02023-02-09
CVE-2023-21420 [HIGH] CWE-134 CVE-2023-21420: Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.
nvd