Android
CVEs (475)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21042 | Hig | 0.70 | 8.8 | 0.33 | KEV | Sep 12, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | |
| CVE-2025-21043 | Hig | 0.69 | 8.8 | 0.02 | KEV | Sep 12, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. | |
| CVE-2020-8899 | Cri | 0.64 | 9.8 | 0.06 | May 6, 2020 | There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable phone can trigger a heap-based buffer overflow in the Quram… | ||
| CVE-2023-21456 | Cri | 0.59 | 9.0 | 0.00 | Mar 16, 2023 | Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid. | ||
| CVE-2021-25487 | Hig | 0.59 | 7.3 | 0.01 | KEV | Oct 6, 2021 | Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer. | |
| CVE-2025-20936 | Hig | 0.57 | 8.8 | 0.00 | Apr 8, 2025 | Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to escalate their privileges to root. | ||
| CVE-2023-21480 | Hig | 0.55 | 8.5 | 0.00 | Sep 3, 2025 | Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2025-20979 | Hig | 0.55 | 8.4 | 0.00 | May 7, 2025 | Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code. | ||
| CVE-2024-34620 | Hig | 0.55 | 8.4 | 0.00 | Aug 7, 2024 | Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service. | ||
| CVE-2024-20845 | Hig | 0.55 | 8.4 | 0.00 | Apr 2, 2024 | Out-of-bounds write vulnerability while releasing memory in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2024-20844 | Hig | 0.55 | 8.4 | 0.00 | Apr 2, 2024 | Out-of-bounds write vulnerability while parsing remaining codewords in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2024-20813 | Hig | 0.55 | 8.4 | 0.00 | Feb 6, 2024 | Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2024-20812 | Hig | 0.55 | 8.4 | 0.00 | Feb 6, 2024 | Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2023-42537 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write. | ||
| CVE-2023-42536 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write. | ||
| CVE-2023-42535 | Hig | 0.55 | 8.4 | 0.00 | Nov 7, 2023 | Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2023-30692 | Hig | 0.55 | 8.5 | 0.00 | Oct 4, 2023 | Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2023-30690 | Hig | 0.55 | 8.5 | 0.00 | Oct 4, 2023 | Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2023-30710 | Hig | 0.55 | 8.5 | 0.00 | Sep 6, 2023 | Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities. | ||
| CVE-2023-30691 | Hig | 0.55 | 8.4 | 0.00 | Aug 10, 2023 | Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation. |
- risk 0.70cvss 8.8epss 0.33
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
- risk 0.69cvss 8.8epss 0.02
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.06
There is a buffer overwrite vulnerability in the Quram qmg library of Samsung's Android OS versions O(8.x), P(9.0) and Q(10.0). An unauthenticated, unauthorized attacker sending a specially crafted MMS to a vulnerable phone can trigger a heap-based buffer overflow in the Quram…
- risk 0.59cvss 9.0epss 0.00
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
- risk 0.59cvss 7.3epss 0.01
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
- risk 0.57cvss 8.8epss 0.00
Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to escalate their privileges to root.
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.55cvss 8.4epss 0.00
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.
- risk 0.55cvss 8.4epss 0.00
Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.
- risk 0.55cvss 8.4epss 0.00
Out-of-bounds write vulnerability while releasing memory in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.
- risk 0.55cvss 8.4epss 0.00
Out-of-bounds write vulnerability while parsing remaining codewords in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.
- risk 0.55cvss 8.4epss 0.00
Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.
- risk 0.55cvss 8.4epss 0.00
Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.
- risk 0.55cvss 8.4epss 0.00
An improper input validation in get_head_crc in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
- risk 0.55cvss 8.4epss 0.00
An improper input validation in saped_dec in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
- risk 0.55cvss 8.4epss 0.00
Out-of-bounds Write in read_block of vold prior to SMR Nov-2023 Release 1 allows local attacker to execute arbitrary code.
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in Evaluator prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in Duo prior to SMR Oct-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.55cvss 8.5epss 0.00
Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.
- risk 0.55cvss 8.4epss 0.00
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to privilege escalation.
Page 1 of 24