cbcvebase.

Samsung Android vulnerabilities

465 known vulnerabilities affecting samsung/android.

Total CVEs
465
CISA KEV
12
actively exploited
Public exploits
1
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH164MEDIUM226LOW66

Vulnerabilities

Page 9 of 24
CVE-2023-21497P3HIGHCVSS 7.8v13.02023-05-04
CVE-2023-21497 [HIGH] CWE-134 CVE-2023-21497: Use of externally-controlled format string vulnerability in mPOS TUI trustlet prior to SMR May-2023 Use of externally-controlled format string vulnerability in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the memory address.
nvd
CVE-2024-20892P3HIGHCVSS 7.8v12.0v13.0+1 more2024-07-02
CVE-2024-20892 [HIGH] CWE-347 CVE-2024-20892: Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local at Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20992P3HIGHCVSS 7.7v13.0v14.0+1 more2025-06-04
CVE-2025-20992 [HIGH] CWE-125 CVE-2025-20992: Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local at Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory.
nvd
CVE-2024-20888P3HIGHCVSS 7.8v12.0v13.0+1 more2024-07-02
CVE-2024-20888 [HIGH] CVE-2024-20888: Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launc Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
nvd
CVE-2023-21474P3HIGHCVSS 7.1v11.0v12.0+1 more2025-09-03
CVE-2023-21474 [HIGH] CVE-2023-21474: Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.
nvd
CVE-2026-21018P3MEDIUMCVSS 6.7v14.0v15.0+1 more2026-05-13
CVE-2026-21018 [MEDIUM] CWE-787 CVE-2026-21018: Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.
nvd
CVE-2026-20982P3MEDIUMCVSS 6.0v14.0v15.0+1 more2026-02-04
CVE-2026-20982 [MEDIUM] CWE-22 CVE-2026-20982: Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker t Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.
nvd
CVE-2024-34676P4HIGHCVSS 7.3v12.0v13.0+1 more2024-11-06
CVE-2024-34676 [HIGH] CWE-787 CVE-2024-34676: Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 a Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability.
nvd
CVE-2025-20903P4HIGHCVSS 7.3v12.0v13.0+2 more2025-03-06
CVE-2025-20903 [HIGH] CVE-2025-20903: Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local atta Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-34587P3MEDIUMCVSS 6.8v12.0v13.0+1 more2024-07-02
CVE-2024-34587 [MEDIUM] CVE-2024-34587: Improper input validation in parsing application information from RTCP packet in librtp.so prior to Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
nvd
CVE-2024-20865P3MEDIUMCVSS 6.8v12.0v13.0+1 more2024-05-07
CVE-2024-20865 [MEDIUM] CVE-2024-20865: Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to fla Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.
nvd
CVE-2026-20980P3MEDIUMCVSS 6.8v14.0v15.0+1 more2026-02-04
CVE-2026-20980 [MEDIUM] CVE-2026-20980: Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execut Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.
nvd
CVE-2026-20981P4MEDIUMCVSS 6.6v14.0v15.0+1 more2026-02-04
CVE-2026-20981 [MEDIUM] CVE-2026-20981: Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physica Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.
nvd
CVE-2026-20968P4MEDIUMCVSS 6.7v13.0v14.0+2 more2026-01-09
CVE-2026-20968 [MEDIUM] CWE-416 CVE-2026-20968: Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execu Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.
nvd
CVE-2025-21080P4HIGHCVSS 7.1v15.0v16.02025-12-02
CVE-2025-21080 [HIGH] CVE-2025-21080: Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Releas Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.
nvd
CVE-2024-20862P4MEDIUMCVSS 6.7v11.0v12.0+2 more2024-05-07
CVE-2024-20862 [MEDIUM] CWE-787 CVE-2024-20862: Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.
nvd
CVE-2024-49401P4HIGHCVSS 7.1v13.0v14.02024-11-06
CVE-2024-49401 [HIGH] CVE-2024-49401: Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attac Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities.
nvd
CVE-2024-34679P4HIGHCVSS 7.1v14.02024-11-06
CVE-2024-34679 [HIGH] CWE-276 CVE-2024-34679: Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to acc Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.
nvd
CVE-2023-42561P4MEDIUMCVSS 6.8≥ 11.0, < 14.0v14.02023-12-05
CVE-2023-42561 [MEDIUM] CWE-787 CVE-2023-42561: Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physic Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.
nvd
CVE-2026-21003P4MEDIUMCVSS 6.8v14.0v15.0+1 more2026-04-13
CVE-2026-21003 [MEDIUM] CVE-2026-21003: Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 al Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions.
nvd