Android
CVEs (475)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-20941 | Med | 0.40 | 6.2 | 0.00 | Apr 8, 2025 | Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device. | ||
| CVE-2024-34662 | Med | 0.40 | 6.2 | 0.00 | Oct 8, 2024 | Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors. | ||
| CVE-2024-34655 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager. | ||
| CVE-2024-34654 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege. | ||
| CVE-2024-34651 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files. | ||
| CVE-2024-34645 | Med | 0.40 | 6.1 | 0.00 | Sep 4, 2024 | Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications. | ||
| CVE-2024-34637 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34609 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34608 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34607 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34606 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34605 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34604 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-20893 | Med | 0.40 | 6.1 | 0.00 | Jul 2, 2024 | Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption. | ||
| CVE-2024-20884 | Med | 0.40 | 6.2 | 0.00 | Jun 4, 2024 | Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API. | ||
| CVE-2024-20883 | Med | 0.40 | 6.2 | 0.00 | Jun 4, 2024 | Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API. | ||
| CVE-2024-20876 | Med | 0.40 | 6.1 | 0.00 | Jun 4, 2024 | Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption. | ||
| CVE-2024-20872 | Med | 0.40 | 6.2 | 0.00 | May 7, 2024 | Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE. | ||
| CVE-2024-20806 | Med | 0.40 | 6.2 | 0.00 | Jan 4, 2024 | Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data. | ||
| CVE-2023-42531 | Med | 0.40 | 6.2 | 0.00 | Nov 7, 2023 | Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background. |
- risk 0.40cvss 6.2epss 0.00
Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.
- risk 0.40cvss 6.2epss 0.00
Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors.
- risk 0.40cvss 6.2epss 0.00
Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.
- risk 0.40cvss 6.2epss 0.00
Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.
- risk 0.40cvss 6.2epss 0.00
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.
- risk 0.40cvss 6.2epss 0.00
Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.
- risk 0.40cvss 6.2epss 0.00
Incorrect use of privileged API vulnerability in getSemBatteryUsageStats in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.
- risk 0.40cvss 6.2epss 0.00
Incorrect use of privileged API vulnerability in registerBatteryStatsCallback in BatteryStatsService prior to SMR Jun-2024 Release 1 allows local attackers to use privileged API.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.
- risk 0.40cvss 6.2epss 0.00
Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.
- risk 0.40cvss 6.2epss 0.00
Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.
- risk 0.40cvss 6.2epss 0.00
Improper access control vulnerability in SmsController prior to SMR Nov-2023 Release1 allows local attackers to bypass restrictions on starting activities from the background.
Page 10 of 24