cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 6 of 24
CVE-2024-20901P3HIGHCVSS 7.8v12.0v13.0+1 more2024-07-02
CVE-2024-20901 [HIGH] CWE-787 CVE-2024-20901: Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2023-30679P3HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30679 [HIGH] CVE-2023-30679: Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to e Improper access control in HDCP trustlet prior to SMR Aug-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2026-20983P3HIGHCVSS 7.8v14.0v15.02026-02-04
CVE-2026-20983 [HIGH] CVE-2026-20983: Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege.
nvd
CVE-2025-20957P3HIGHCVSS 7.8v13.0v14.0+1 more2025-05-07
CVE-2025-20957 [HIGH] CVE-2025-20957: Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.
nvd
CVE-2023-21480P3HIGHCVSS 7.8v11.0v12.0+1 more2025-09-03
CVE-2023-21480 [HIGH] CVE-2023-21480: Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local att Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2026-21010P3HIGHCVSS 7.8v14.0v15.0+1 more2026-04-13
CVE-2026-21010 [HIGH] CVE-2026-21010: Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to t Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.
nvd
CVE-2026-21029P3HIGHCVSS 7.8v14.0v15.0+1 more2026-06-05
CVE-2026-21029 [HIGH] CVE-2026-21029: Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Re Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.
nvd
CVE-2026-21031P3HIGHCVSS 7.8v15.0v16.02026-06-05
CVE-2026-21031 [HIGH] CWE-863 CVE-2026-21031: Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch a Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.
nvd
CVE-2023-42530P3HIGHCVSS 7.5v11.0v12.0+1 more2023-11-07
CVE-2023-42530 [HIGH] CVE-2023-42530: Improper access control vulnerability in SecSettings prior to SMR Nov-2023 Release 1 allows attacker Improper access control vulnerability in SecSettings prior to SMR Nov-2023 Release 1 allows attackers to enable Wi-Fi and Wi-Fi Direct without User Interaction.
nvd
CVE-2023-42566P3HIGHCVSS 7.8≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42566 [HIGH] CWE-787 CVE-2023-42566: Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-42529P3HIGHCVSS 7.8v11.0v12.0+1 more2023-11-07
CVE-2023-42529 [HIGH] CWE-787 CVE-2023-42529: Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attacker Out-of-bound write vulnerability in libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-30650P3HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30650 [HIGH] CWE-787 CVE-2023-30650: Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release Out of bounds read and write in callrunTspCmd of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-30651P3HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30651 [HIGH] CWE-787 CVE-2023-30651: Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Releas Out of bounds read and write in callgetTspsysfs of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-30653P3HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30653 [HIGH] CWE-787 CVE-2023-30653: Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Releas Out of bounds read and write in enableTspDevice of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-30652P3HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30652 [HIGH] CWE-787 CVE-2023-30652: Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Re Out of bounds read and write in callrunTspCmdNoRead of sysinput HAL service prior to SMR Jul-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-21501P3HIGHCVSS 7.8v13.02023-05-04
CVE-2023-21501 [HIGH] CWE-20 CVE-2023-21501: Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 all Improper input validation vulnerability in mPOS fiserve trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.
nvd
CVE-2023-30656P3HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30656 [HIGH] CWE-20 CVE-2023-30656: Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attack Improper input validation vulnerability in LSOItemData prior to SMR Jul-2023 Release 1 allows attackers to launch certain activities.
nvd
CVE-2023-21502P3HIGHCVSS 7.8v12.0v13.02023-05-04
CVE-2023-21502 [HIGH] CWE-20 CVE-2023-21502: Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 a Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands.
nvd
CVE-2023-30663P3HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30663 [HIGH] CWE-20 CVE-2023-30663: Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul- Improper input validation vulnerability in OemPersonalizationSetLock in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.
nvd
CVE-2023-30666P3HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30666 [HIGH] CWE-787 CVE-2023-30666: Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Improper input validation vulnerability in DoOemImeiSetPreconfig in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds write.
nvd
Samsung Android vulnerabilities | cvebase