Samsung Android vulnerabilities
448 known vulnerabilities affecting samsung/android.
Total CVEs
448
CISA KEV
12
actively exploited
Public exploits
0
Exploited in wild
10
Severity breakdown
CRITICAL9HIGH160MEDIUM218LOW61
Vulnerabilities
Page 6 of 23
CVE-2025-20964HIGHCVSS 7.8v13.0v14.0+1 more2025-05-07
CVE-2025-20964 [HIGH] CWE-787 CVE-2025-20964: Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows lo
Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2025-20954MEDIUMCVSS 5.5v13.0v14.0+1 more2025-05-07
CVE-2025-20954 [MEDIUM] CVE-2025-20954: Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 a
Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20955MEDIUMCVSS 5.5v13.0v14.0+1 more2025-05-07
CVE-2025-20955 [MEDIUM] CVE-2025-20955: Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR M
Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.
nvd
CVE-2025-20961MEDIUMCVSS 5.5v13.0v14.0+1 more2025-05-07
CVE-2025-20961 [MEDIUM] CVE-2025-20961: Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025
Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.
nvd
CVE-2025-20937MEDIUMCVSS 6.7v13.0v14.0+1 more2025-05-07
CVE-2025-20937 [MEDIUM] CWE-787 CVE-2025-20937: Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged at
Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
nvd
CVE-2025-20958MEDIUMCVSS 4.4v13.0v14.0+1 more2025-05-07
CVE-2025-20958 [MEDIUM] CVE-2025-20958: Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.
nvd
CVE-2025-20959MEDIUMCVSS 5.5v13.0v14.0+1 more2025-05-07
CVE-2025-20959 [MEDIUM] CVE-2025-20959: Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Releas
Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.
nvd
CVE-2025-20962MEDIUMCVSS 4.0v13.0v14.0+1 more2025-05-07
CVE-2025-20962 [MEDIUM] CVE-2025-20962: Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.
nvd
CVE-2025-20953MEDIUMCVSS 4.4v13.0v14.0+1 more2025-05-07
CVE-2025-20953 [MEDIUM] CVE-2025-20953: Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.
nvd
CVE-2025-20960LOWCVSS 3.3v13.0v14.0+1 more2025-05-07
CVE-2025-20960 [LOW] CVE-2025-20960: Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 a
Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.
nvd
CVE-2025-20952MEDIUMCVSS 5.5v15.02025-04-09
CVE-2025-20952 [MEDIUM] CVE-2025-20952: Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to acc
Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.
nvd
CVE-2025-20936HIGHCVSS 7.8v13.0v14.0+1 more2025-04-08
CVE-2025-20936 [HIGH] CVE-2025-20936: Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with
Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to escalate their privileges to root.
nvd
CVE-2025-20944HIGHCVSS 7.1v13.0v14.0+1 more2025-04-08
CVE-2025-20944 [HIGH] CWE-125 CVE-2025-20944: Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows loca
Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.
nvd
CVE-2025-20948HIGHCVSS 7.1v13.0v14.0+1 more2025-04-08
CVE-2025-20948 [HIGH] CWE-125 CVE-2025-20948: Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allo
Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
nvd
CVE-2025-20942MEDIUMCVSS 4.4v13.0v14.0+1 more2025-04-08
CVE-2025-20942 [MEDIUM] CVE-2025-20942: Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Relea
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.
nvd
CVE-2025-20947MEDIUMCVSS 5.5v13.0v14.0+1 more2025-04-08
CVE-2025-20947 [MEDIUM] CVE-2025-20947: Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20934MEDIUMCVSS 5.5fixed in 14.0v14.02025-04-08
CVE-2025-20934 [MEDIUM] CWE-926 CVE-2025-20934: Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.
nvd
CVE-2025-20943MEDIUMCVSS 4.4v13.0v14.0+1 more2025-04-08
CVE-2025-20943 [MEDIUM] CWE-787 CVE-2025-20943: Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attack
Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.
nvd
CVE-2025-20938MEDIUMCVSS 5.5v14.02025-04-08
CVE-2025-20938 [MEDIUM] CVE-2025-20938: Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to
Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.
nvd
CVE-2025-20941LOWCVSS 3.3v13.0v14.0+1 more2025-04-08
CVE-2025-20941 [LOW] CVE-2025-20941: Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access t
Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.
nvd