cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 8 of 24
CVE-2023-21430P3HIGHCVSS 7.8v10.0v11.0+2 more2023-02-09
CVE-2023-21430 [HIGH] CWE-125 CVE-2023-21430: An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung. An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.
nvd
CVE-2023-30664P3HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30664 [HIGH] CWE-20 CVE-2023-30664: Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows l Improper input validation vulnerability in RegisteredMSISDN prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2023-30655P3HIGHCVSS 7.8v11.0v12.0+1 more2023-07-06
CVE-2023-30655 [HIGH] CWE-20 CVE-2023-30655: Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local Improper input validation vulnerability in SCEPProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2023-30658P3HIGHCVSS 7.8v13.02023-07-06
CVE-2023-30658 [HIGH] CWE-20 CVE-2023-30658: Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local Improper input validation vulnerability in DataProfile prior to SMR Jul-2023 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2023-30710P3HIGHCVSS 7.8v11.0v12.0+1 more2023-09-06
CVE-2023-30710 [HIGH] CVE-2023-30710: Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local atta Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2025-20890P3HIGHCVSS 7.8v12.0v13.0+1 more2025-02-04
CVE-2025-20890 [HIGH] CWE-787 CVE-2025-20890: Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20888P3HIGHCVSS 7.8v12.0v13.0+1 more2025-02-04
CVE-2025-20888 [HIGH] CWE-787 CVE-2025-20888: Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Rel Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2023-21491P3HIGHCVSS 7.8v12.0v13.02023-05-04
CVE-2023-21491 [HIGH] CWE-284 CVE-2023-21491: Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local a Improper access control vulnerability in ThemeManager prior to SMR May-2023 Release 1 allows local attackers to write arbitrary files with system privilege.
nvd
CVE-2024-34615P3HIGHCVSS 7.8v12.0v13.0+1 more2024-08-07
CVE-2024-34615 [HIGH] CWE-787 CVE-2024-34615: Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause mem Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.
nvd
CVE-2023-21484P3HIGHCVSS 7.8v11.0v12.0+1 more2023-05-04
CVE-2023-21484 [HIGH] CWE-287 CVE-2023-21484: Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attack Improper access control vulnerability in AppLock prior to SMR May-2023 Release 1 allows local attackers without proper permission to execute a privileged operation.
nvd
CVE-2023-21488P3HIGHCVSS 7.8v11.0v12.0+1 more2023-05-04
CVE-2023-21488 [HIGH] CWE-284 CVE-2023-21488: Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attacker Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.
nvd
CVE-2025-20963P3HIGHCVSS 7.8v13.0v14.0+1 more2025-05-07
CVE-2025-20963 [HIGH] CWE-787 CVE-2025-20963: Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2025-20964P3HIGHCVSS 7.8v13.0v14.0+1 more2025-05-07
CVE-2025-20964 [HIGH] CWE-787 CVE-2025-20964: Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows lo Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.
nvd
CVE-2024-34662P3HIGHCVSS 7.8v12.0v13.0+1 more2024-10-08
CVE-2024-34662 [HIGH] CVE-2024-34662: Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors.
nvd
CVE-2024-34620P3HIGHCVSS 7.8v13.0v14.02024-08-07
CVE-2024-34620 [HIGH] CVE-2024-34620: Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attacker Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.
nvd
CVE-2026-21020P3HIGHCVSS 7.8v14.0v15.0+1 more2026-05-13
CVE-2026-21020 [HIGH] CVE-2026-21020: Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows lo Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.
nvd
CVE-2025-58477P3MEDIUMCVSS 6.5v13.0v14.0+2 more2025-12-02
CVE-2025-58477 [MEDIUM] CWE-787 CVE-2025-58477: Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 all Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
nvd
CVE-2023-21457P3HIGHCVSS 8.1v11.0v12.0+1 more2023-03-16
CVE-2023-21457 [HIGH] CWE-284 CVE-2023-21457: Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers Improper access control vulnerability in Bluetooth prior to SMR Mar-2023 Release 1 allows attackers to send file via Bluetooth without related permission.
nvd
CVE-2023-21445P3HIGHCVSS 7.8v11.0v12.0+1 more2023-02-09
CVE-2023-21445 [HIGH] CWE-284 CVE-2023-21445: Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03 Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1.03.501 in Android S(12) and 14.1.00.422 in Android T(13) allows local attacker to write file with MyFiles privilege via implicit intent.
nvd
CVE-2023-21498P3HIGHCVSS 7.8v13.02023-05-04
CVE-2023-21498 [HIGH] CWE-20 CVE-2023-21498: Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-20 Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.
nvd