Samsung Android vulnerabilities
448 known vulnerabilities affecting samsung/android.
Total CVEs
448
CISA KEV
12
actively exploited
Public exploits
0
Exploited in wild
10
Severity breakdown
CRITICAL9HIGH160MEDIUM218LOW61
Vulnerabilities
Page 9 of 23
CVE-2024-34666HIGHCVSS 8.8v12.0v13.0+1 more2024-10-08
CVE-2024-34666 [HIGH] CWE-787 CVE-2024-34666: Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-
Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34667HIGHCVSS 8.8v12.0v13.0+1 more2024-10-08
CVE-2024-34667 [HIGH] CWE-787 CVE-2024-34667: Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allo
Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34638HIGHCVSS 7.1v12.0v13.0+1 more2024-09-04
CVE-2024-34638 [HIGH] CWE-755 CVE-2024-34638: Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows lo
Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.
nvd
CVE-2024-34654MEDIUMCVSS 5.5v13.0v14.02024-09-04
CVE-2024-34654 [MEDIUM] CVE-2024-34654: Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows
Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.
nvd
CVE-2024-34637MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34637 [MEDIUM] CVE-2024-34637: Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and S
Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.
nvd
CVE-2024-34643MEDIUMCVSS 5.5v14.02024-09-04
CVE-2024-34643 [MEDIUM] CVE-2024-34643: Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 a
Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34645MEDIUMCVSS 4.6v12.0v13.02024-09-04
CVE-2024-34645 [MEDIUM] CVE-2024-34645: Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers t
Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.
nvd
CVE-2024-34651MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34651 [MEDIUM] CWE-863 CVE-2024-34651: Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
nvd
CVE-2024-34646MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34646 [MEDIUM] CVE-2024-34646: Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attacker
Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.
nvd
CVE-2024-34648MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34648 [MEDIUM] CWE-276 CVE-2024-34648: Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allo
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.
nvd
CVE-2024-34653MEDIUMCVSS 4.6v12.0v13.0+1 more2024-09-04
CVE-2024-34653 [MEDIUM] CWE-22 CVE-2024-34653: Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access direc
Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.
nvd
CVE-2024-34639MEDIUMCVSS 4.6v12.0v13.0+1 more2024-09-04
CVE-2024-34639 [MEDIUM] CWE-755 CVE-2024-34639: Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows ph
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
nvd
CVE-2024-34655MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34655 [MEDIUM] CVE-2024-34655: Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows
Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.
nvd
CVE-2024-34644MEDIUMCVSS 5.5v14.02024-09-04
CVE-2024-34644 [MEDIUM] CVE-2024-34644: Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allow
Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34642MEDIUMCVSS 4.6v12.0v13.0+1 more2024-09-04
CVE-2024-34642 [MEDIUM] CWE-863 CVE-2024-34642: Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to t
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
nvd
CVE-2024-34647MEDIUMCVSS 5.5v12.0v13.0+1 more2024-09-04
CVE-2024-34647 [MEDIUM] CVE-2024-34647: Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local
Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.
nvd
CVE-2024-34649LOWCVSS 2.4v14.02024-09-04
CVE-2024-34649 [LOW] CVE-2024-34649: Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 al
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.
nvd
CVE-2024-34650LOWCVSS 3.3v14.02024-09-04
CVE-2024-34650 [LOW] CWE-863 CVE-2024-34650: Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
nvd
CVE-2024-34640LOWCVSS 3.3v12.0v13.0+1 more2024-09-04
CVE-2024-34640 [LOW] CVE-2024-34640: Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows loc
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
nvd
CVE-2024-34652LOWCVSS 3.3v12.0v13.0+1 more2024-09-04
CVE-2024-34652 [LOW] CWE-863 CVE-2024-34652: Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
nvd