cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 22 of 24
CVE-2024-34640P4LOWCVSS 3.3v12.0v13.0+1 more2024-09-04
CVE-2024-34640 [LOW] CVE-2024-34640: Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows loc Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
nvd
CVE-2023-30682P4LOWCVSS 3.3v13.02023-08-10
CVE-2023-30682 [LOW] CVE-2023-30682: Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call si Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.
nvd
CVE-2023-30683P4LOWCVSS 3.3v13.02023-08-10
CVE-2023-30683 [LOW] CVE-2023-30683: Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call en Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.
nvd
CVE-2023-30684P4LOWCVSS 3.3v13.02023-08-10
CVE-2023-30684 [LOW] CVE-2023-30684: Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.
nvd
CVE-2024-34650P4LOWCVSS 3.3v14.02024-09-04
CVE-2024-34650 [LOW] CWE-863 CVE-2024-34650: Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
nvd
CVE-2024-34652P4LOWCVSS 3.3v12.0v13.0+1 more2024-09-04
CVE-2024-34652 [LOW] CWE-863 CVE-2024-34652: Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
nvd
CVE-2025-20960P4LOWCVSS 3.3v13.0v14.0+1 more2025-05-07
CVE-2025-20960 [LOW] CVE-2025-20960: Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 a Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.
nvd
CVE-2023-21469P4LOWCVSS 3.3v11.0v12.0+1 more2025-09-03
CVE-2023-21469 [LOW] CVE-2023-21469: Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local atta Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.
nvd
CVE-2023-21470P4LOWCVSS 3.3v11.0v12.0+1 more2025-09-03
CVE-2023-21470 [LOW] CVE-2023-21470: Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local atta Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.
nvd
CVE-2025-20985P4LOWCVSS 3.3v13.0v14.0+1 more2025-06-04
CVE-2025-20985 [LOW] CVE-2025-20985: Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privilege Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items.
nvd
CVE-2026-21027P4LOWCVSS 3.3v14.0v15.0+1 more2026-06-05
CVE-2026-21027 [LOW] CVE-2026-21027: Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 all Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.
nvd
CVE-2026-20992P4LOWCVSS 3.3v13.0v14.0+2 more2026-03-16
CVE-2026-20992 [LOW] CWE-863 CVE-2026-20992: Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
nvd
CVE-2023-21466P4LOWCVSS 3.3v11.0v12.0+1 more2025-09-03
CVE-2023-21466 [LOW] CWE-287 CVE-2023-21466: PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Releas PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.
nvd
CVE-2023-21512P4LOWCVSS 3.3v11.0v12.0+1 more2023-06-28
CVE-2023-21512 [LOW] CWE-269 CVE-2023-21512: Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows l Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.
nvd
CVE-2023-30717P4LOWCVSS 3.3v11.0v12.0+1 more2023-09-06
CVE-2023-30717 [LOW] CVE-2023-30717: Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows atta Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to get unresettable identifiers.
nvd
CVE-2024-20860P4LOWCVSS 3.3v14.02024-05-07
CVE-2024-20860 [LOW] CVE-2024-20860: Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.
nvd
CVE-2023-30685P4LOWCVSS 3.3v11.0v12.0+1 more2023-08-10
CVE-2023-30685 [LOW] CVE-2023-30685: Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakc Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
nvd
CVE-2023-30640P4LOWCVSS 3.3v11.0v12.0+1 more2023-07-06
CVE-2023-30640 [LOW] CVE-2023-30640: Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allow Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.
nvd
CVE-2023-21487P4LOWCVSS 3.3v11.0v12.0+1 more2023-05-04
CVE-2023-21487 [LOW] CWE-287 CVE-2023-21487: Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.
nvd
CVE-2024-20847P4LOWCVSS 3.3v12.0v13.0+1 more2024-04-02
CVE-2024-20847 [LOW] CVE-2024-20847: Improper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allow Improper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allows local attackers to read sdcard information.
nvd
Samsung Android vulnerabilities | cvebase