cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 23 of 24
CVE-2024-20834P4LOWCVSS 3.3v11.0v12.0+2 more2024-03-05
CVE-2024-20834 [LOW] CVE-2024-20834: The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.
nvd
CVE-2024-34677P4LOWCVSS 3.3v12.0v13.0+1 more2024-11-06
CVE-2024-34677 [LOW] CWE-922 CVE-2024-34677: Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.
nvd
CVE-2024-34641P4LOWCVSS 3.3v12.0v13.0+1 more2024-09-04
CVE-2024-34641 [LOW] CVE-2024-34641: Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allo Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.
nvd
CVE-2024-20811P4LOWCVSS 3.3v11.0v12.0+2 more2024-02-06
CVE-2024-20811 [LOW] CVE-2024-20811: Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.
nvd
CVE-2023-30718P4LOWCVSS 3.3v11.0v12.0+1 more2023-09-06
CVE-2023-30718 [LOW] CVE-2023-30718: Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity Improper export of android application components vulnerability in WifiApAutoHotspotEnablingActivity prior to SMR Sep-2023 Release 1 allows local attacker to change a Auto Hotspot setting.
nvd
CVE-2023-30700P4LOWCVSS 3.3v11.0v12.0+1 more2023-08-10
CVE-2023-30700 [LOW] CVE-2023-30700: PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Rel PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.
nvd
CVE-2024-20885P4LOWCVSS 3.3v14.02024-06-04
CVE-2024-20885 [LOW] CVE-2024-20885: Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.
nvd
CVE-2024-34583P4LOWCVSS 3.3v12.0v13.0+1 more2024-07-02
CVE-2024-34583 [LOW] CVE-2024-34583: Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.
nvd
CVE-2024-34618P4LOWCVSS 3.3v12.0v13.0+1 more2024-08-07
CVE-2024-34618 [LOW] CVE-2024-34618: Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.
nvd
CVE-2024-34617P4LOWCVSS 3.3v14.02024-08-07
CVE-2024-34617 [LOW] CWE-276 CVE-2024-34617: Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows loc Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.
nvd
CVE-2024-34586P4LOWCVSS 3.3v12.0v13.0+1 more2024-07-02
CVE-2024-34586 [LOW] CVE-2024-34586: Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local att Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.
nvd
CVE-2025-21000P4LOWCVSS 3.3v13.0v14.0+1 more2025-07-08
CVE-2025-21000 [LOW] CVE-2025-21000: Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.
nvd
CVE-2026-20972P4LOWCVSS 3.3v13.0v14.0+2 more2026-01-09
CVE-2026-20972 [LOW] CVE-2026-20972: Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.
nvd
CVE-2025-21026P4LOWCVSS 3.3v13.0v14.0+2 more2025-09-03
CVE-2025-21026 [LOW] CVE-2025-21026: Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows lo Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.
nvd
CVE-2024-20810P4LOWCVSS 3.3v12.0v13.02024-02-06
CVE-2024-20810 [LOW] CWE-1021 CVE-2024-20810: Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.
nvd
CVE-2023-30719P4LOWCVSS 3.3v11.0v12.0+1 more2023-09-06
CVE-2023-30719 [LOW] CVE-2023-30719: Exposure of Sensitive Information vulnerability in InboundSmsHandler prior to SMR Sep-2023 Release 1 Exposure of Sensitive Information vulnerability in InboundSmsHandler prior to SMR Sep-2023 Release 1 allows local attackers to access certain message data.
nvd
CVE-2026-20989P4LOWCVSS 2.4v16.02026-03-16
CVE-2026-20989 [LOW] CWE-347 CVE-2026-20989: Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 al Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.
nvd
CVE-2025-20999P4LOWCVSS 2.1v13.0v14.0+1 more2025-07-08
CVE-2025-20999 [LOW] CWE-863 CVE-2025-20999: Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Rel Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.
nvd
CVE-2023-21454P4LOWCVSS 2.4v11.0v12.0+1 more2023-03-16
CVE-2023-21454 [LOW] CWE-285 CVE-2023-21454: Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.
nvd
CVE-2024-34682P4LOWCVSS 2.4v14.02024-11-06
CVE-2024-34682 [LOW] CVE-2024-34682: Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to acce Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi password in Maintenance Mode.
nvd