Android
CVEs (475)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21498 | Med | 0.39 | 6.0 | 0.00 | May 4, 2023 | Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory. | ||
| CVE-2023-21453 | Med | 0.39 | 6.0 | 0.00 | Mar 16, 2023 | Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data. | ||
| CVE-2025-21032 | Med | 0.38 | 5.9 | 0.00 | Sep 3, 2025 | Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions. | ||
| CVE-2023-21468 | Med | 0.38 | 5.9 | 0.00 | Sep 3, 2025 | Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission. | ||
| CVE-2025-20892 | Med | 0.38 | 5.9 | 0.00 | Feb 4, 2025 | Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-49410 | Med | 0.38 | 5.9 | 0.00 | Dec 3, 2024 | Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code. | ||
| CVE-2024-34678 | Med | 0.38 | 5.9 | 0.00 | Nov 6, 2024 | Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. | ||
| CVE-2024-34586 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy. | ||
| CVE-2024-20901 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2024-20889 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices. | ||
| CVE-2024-20846 | Med | 0.38 | 5.9 | 0.00 | Apr 2, 2024 | Out-of-bounds write vulnerability while decoding hcr of libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code. | ||
| CVE-2023-52432 | Med | 0.38 | 5.9 | 0.00 | Mar 5, 2024 | Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2023-42570 | Med | 0.38 | 5.9 | 0.00 | Dec 5, 2023 | Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN. | ||
| CVE-2023-42538 | Med | 0.38 | 5.9 | 0.00 | Nov 7, 2023 | An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write. | ||
| CVE-2023-42532 | Med | 0.38 | 5.9 | 0.00 | Nov 7, 2023 | Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information. | ||
| CVE-2023-21421 | Med | 0.38 | 5.9 | 0.00 | Feb 9, 2023 | Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN. | ||
| CVE-2025-21072 | Med | 0.37 | 5.7 | 0.00 | Dec 2, 2025 | Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2025-21071 | Med | 0.37 | 5.7 | 0.00 | Nov 5, 2025 | Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2025-21044 | Med | 0.37 | 5.7 | 0.00 | Oct 10, 2025 | Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2024-20866 | Med | 0.37 | 5.7 | 0.00 | May 7, 2024 | Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step. |
- risk 0.39cvss 6.0epss 0.00
Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.
- risk 0.39cvss 6.0epss 0.00
Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
- risk 0.38cvss 5.9epss 0.00
Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.
- risk 0.38cvss 5.9epss 0.00
Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.
- risk 0.38cvss 5.9epss 0.00
Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. User interaction is required for triggering this vulnerability.
- risk 0.38cvss 5.9epss 0.00
Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.
- risk 0.38cvss 5.9epss 0.00
Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.
- risk 0.38cvss 5.9epss 0.00
Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.
- risk 0.38cvss 5.9epss 0.00
Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.38cvss 5.9epss 0.00
Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.
- risk 0.38cvss 5.9epss 0.00
Out-of-bounds write vulnerability while decoding hcr of libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.
- risk 0.38cvss 5.9epss 0.00
Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.38cvss 5.9epss 0.00
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.
- risk 0.38cvss 5.9epss 0.00
An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows local attackers to cause out-of-bounds read and write.
- risk 0.38cvss 5.9epss 0.00
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.
- risk 0.38cvss 5.9epss 0.00
Improper Handling of Insufficient Permissions or Privileges vulnerability in KnoxCustomManagerService prior to SMR Jan-2023 Release 1 allows attacker to access device SIM PIN.
- risk 0.37cvss 5.7epss 0.00
Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.37cvss 5.7epss 0.00
Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.37cvss 5.7epss 0.00
Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.37cvss 5.7epss 0.00
Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.
Page 12 of 24