Samsung Android vulnerabilities
465 known vulnerabilities affecting samsung/android.
Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66
Vulnerabilities
Page 7 of 24
CVE-2023-21451P3HIGHCVSS 7.8v12.02023-02-09
CVE-2023-21451 [HIGH] CWE-20 CVE-2023-21451: A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allow
A Stack-based overflow vulnerability in IpcRxEmbmsSessionList in SECRIL prior to Android S(12) allows attacker to cause memory corruptions.
nvd
CVE-2025-20882P3HIGHCVSS 7.8v12.0v13.0+1 more2025-02-04
CVE-2025-20882 [HIGH] CWE-787 CVE-2025-20882: Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-20
Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20881P3HIGHCVSS 7.8v12.0v13.0+1 more2025-02-04
CVE-2025-20881 [HIGH] CWE-787 CVE-2025-20881: Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SM
Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34595P3HIGHCVSS 7.8v12.0v13.0+1 more2024-07-02
CVE-2024-34595 [HIGH] CVE-2024-34595: Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local
Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2023-30691P3HIGHCVSS 7.8v11.0v12.0+1 more2023-08-10
CVE-2023-30691 [HIGH] CWE-266 CVE-2023-30691: Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to pri
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.
nvd
CVE-2024-20848P3HIGHCVSS 7.8v12.0v13.0+1 more2024-04-02
CVE-2024-20848 [HIGH] CWE-787 CVE-2024-20848: Improper Input Validation vulnerability in text parsing implementation of libsdffextractor prior to
Improper Input Validation vulnerability in text parsing implementation of libsdffextractor prior to SMR Apr-2024 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2024-20874P3HIGHCVSS 7.8v13.0v14.02024-06-04
CVE-2024-20874 [HIGH] CVE-2024-20874: Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local
Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2024-20891P3HIGHCVSS 7.8v12.0v13.0+1 more2024-07-02
CVE-2024-20891 [HIGH] CVE-2024-20891: Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows
Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2024-20876P3HIGHCVSS 7.8v12.0v13.0+1 more2024-06-04
CVE-2024-20876 [HIGH] CVE-2024-20876: Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local atta
Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.
nvd
CVE-2024-20835P3HIGHCVSS 7.8v11.0v12.0+2 more2024-03-05
CVE-2024-20835 [HIGH] CVE-2024-20835: Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release
Improper access control vulnerability in CustomFrequencyManagerService prior to SMR Mar-2024 Release 1 allows local attackers to execute privileged behaviors.
nvd
CVE-2024-34585P3HIGHCVSS 7.8v12.0v13.0+1 more2024-07-02
CVE-2024-34585 [HIGH] CVE-2024-34585: Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attack
Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2024-49413P3HIGHCVSS 7.8v13.0v14.02024-12-03
CVE-2024-49413 [HIGH] CWE-347 CVE-2024-49413: Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allo
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.
nvd
CVE-2023-42536P3HIGHCVSS 7.8v11.0v12.0+1 more2023-11-07
CVE-2023-42536 [HIGH] CWE-125 CVE-2023-42536: An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local a
An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
nvd
CVE-2023-42537P3HIGHCVSS 7.8v11.0v12.0+1 more2023-11-07
CVE-2023-42537 [HIGH] CWE-125 CVE-2023-42537: An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows loca
An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
nvd
CVE-2023-42538P3HIGHCVSS 7.8v11.0v12.0+1 more2023-11-07
CVE-2023-42538 [HIGH] CWE-125 CVE-2023-42538: An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows
An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
nvd
CVE-2023-30692P3HIGHCVSS 7.8v11.0v12.0+1 more2023-10-04
CVE-2023-30692 [HIGH] CVE-2023-30692: Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local at
Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2023-21439P3HIGHCVSS 7.8v12.0v13.02023-02-09
CVE-2023-21439 [HIGH] CWE-20 CVE-2023-21439: Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allo
Improper input validation vulnerability in UwbDataTxStatusEvent prior to SMR Feb-2023 Release 1 allows attackers to launch certain activities.
nvd
CVE-2023-30659P3HIGHCVSS 7.8v13.02023-07-06
CVE-2023-30659 [HIGH] CWE-20 CVE-2023-30659: Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local
Improper input validation vulnerability in Transaction prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2023-30657P3HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30657 [HIGH] CWE-20 CVE-2023-30657: Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1
Improper input validation vulnerability in EnhancedAttestationResult prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2023-30690P3HIGHCVSS 7.8v11.0v12.0+1 more2023-10-04
CVE-2023-30690 [HIGH] CWE-20 CVE-2023-30690: Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attacker
Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
nvd