cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 21 of 24
CVE-2025-20962P4MEDIUMCVSS 4.0v13.0v14.0+1 more2025-05-07
CVE-2025-20962 [MEDIUM] CVE-2025-20962: Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.
nvd
CVE-2025-21029P4LOWCVSS 3.3v13.0v14.0+2 more2025-09-03
CVE-2025-21029 [LOW] CVE-2025-21029: Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows loc Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.
nvd
CVE-2024-20900P4LOWCVSS 3.3v12.0v13.0+1 more2024-07-02
CVE-2024-20900 [LOW] CWE-287 CVE-2024-20900: Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
nvd
CVE-2026-21012P4LOWCVSS 3.3v14.0v15.0+1 more2026-04-13
CVE-2026-21012 [LOW] CVE-2026-21012: External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.
nvd
CVE-2024-49422P4LOWCVSS 3.9v13.02024-12-31
CVE-2024-49422 [LOW] CVE-2024-49422: Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.
nvd
CVE-2023-42569P4LOWCVSS 3.3≥ 11.0, < 13.0v13.02023-12-05
CVE-2023-42569 [LOW] CWE-863 CVE-2023-42569: Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.
nvd
CVE-2023-42570P4LOWCVSS 3.3≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42570 [LOW] CVE-2023-42570: Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 al Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.
nvd
CVE-2023-21429P4LOWCVSS 3.3v10.0v11.0+2 more2023-02-09
CVE-2023-21429 [LOW] CWE-285 CVE-2023-21429: Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access S Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
nvd
CVE-2023-30667P4LOWCVSS 3.3v13.02023-07-06
CVE-2023-30667 [LOW] CVE-2023-30667: Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to s Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.
nvd
CVE-2023-21424P4LOWCVSS 3.3v11.0v12.0+1 more2023-02-09
CVE-2023-21424 [LOW] CWE-285 CVE-2023-21424: Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prio Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.
nvd
CVE-2025-20990P4LOWCVSS 3.3v13.0v14.0+1 more2025-08-06
CVE-2025-20990 [LOW] CVE-2025-20990: Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
nvd
CVE-2024-49414P4LOWCVSS 2.4v12.0v13.0+1 more2024-12-03
CVE-2024-49414 [LOW] CVE-2024-49414: Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows phy Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.
nvd
CVE-2023-21428P4LOWCVSS 3.3v11.0v12.0+1 more2023-02-09
CVE-2023-21428 [LOW] CWE-20 CVE-2023-21428: Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attack Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.
nvd
CVE-2023-30732P4LOWCVSS 3.3v13.02023-10-04
CVE-2023-30732 [LOW] CVE-2023-30732: Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.
nvd
CVE-2023-21458P4LOWCVSS 3.3v11.0v12.0+1 more2023-03-16
CVE-2023-21458 [LOW] CWE-269 CVE-2023-21458: Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-20 Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
nvd
CVE-2023-21452P4LOWCVSS 3.3v11.0v12.0+1 more2023-03-16
CVE-2023-21452 [LOW] CWE-285 CVE-2023-21452: Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to ge Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
nvd
CVE-2023-21436P4LOWCVSS 3.3v10.0v11.0+2 more2023-02-09
CVE-2023-21436 [LOW] CWE-285 CVE-2023-21436: Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get Improper usage of implicit intent in Contacts prior to SMR Feb-2023 Release 1 allows attacker to get account ID.
nvd
CVE-2023-30715P4LOWCVSS 3.3v11.0v12.0+1 more2023-09-06
CVE-2023-30715 [LOW] CVE-2023-30715: Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.
nvd
CVE-2024-20872P4LOWCVSS 3.3v14.02024-05-07
CVE-2024-20872 [LOW] CVE-2024-20872: Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.
nvd
CVE-2025-20941P4LOWCVSS 3.3v13.0v14.0+1 more2025-04-08
CVE-2025-20941 [LOW] CVE-2025-20941: Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access t Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.
nvd