Android
CVEs (475)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30731 | Med | 0.37 | 5.7 | 0.00 | Oct 4, 2023 | Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type. | ||
| CVE-2023-21502 | Med | 0.37 | 5.7 | 0.00 | May 4, 2023 | Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands. | ||
| CVE-2023-21422 | Med | 0.37 | 5.7 | 0.00 | Feb 9, 2023 | Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService. | ||
| CVE-2026-21028 | Med | 0.36 | 5.5 | 0.00 | Jun 5, 2026 | Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2026-21026 | Med | 0.36 | 5.5 | 0.00 | Jun 5, 2026 | Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information. | ||
| CVE-2026-21025 | Med | 0.36 | 5.5 | 0.00 | Jun 5, 2026 | Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2026-21017 | Med | 0.36 | 5.5 | 0.00 | Jun 5, 2026 | Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files. | ||
| CVE-2026-21022 | Med | 0.36 | 5.5 | 0.00 | May 13, 2026 | Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2026-21016 | Med | 0.36 | 5.5 | 0.00 | May 13, 2026 | Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2026-21015 | Med | 0.36 | 5.5 | 0.00 | May 13, 2026 | Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier. | ||
| CVE-2026-21023 | Med | 0.36 | 5.5 | 0.00 | Apr 29, 2026 | Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application. | ||
| CVE-2026-20977 | Med | 0.36 | 5.5 | 0.00 | Feb 4, 2026 | Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning. | ||
| CVE-2026-20969 | Med | 0.36 | 5.5 | 0.00 | Jan 9, 2026 | Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-58475 | Med | 0.36 | 5.6 | 0.00 | Dec 2, 2025 | Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2025-21049 | Med | 0.36 | 5.5 | 0.00 | Oct 10, 2025 | Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-21028 | Med | 0.36 | 5.5 | 0.00 | Sep 3, 2025 | Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items. | ||
| CVE-2025-21009 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption. | ||
| CVE-2025-21008 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption. | ||
| CVE-2025-21007 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption. | ||
| CVE-2025-21005 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2025 | Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information. |
- risk 0.37cvss 5.7epss 0.00
Logic error in package installation via debugger command prior to SMR Oct-2023 Release 1 allows physical attacker to install an application that has different build type.
- risk 0.37cvss 5.7epss 0.00
Improper input validation vulnerability in FactoryTest application prior to SMR May-2023 Release 1 allows local attackers to get privilege escalation via debugging commands.
- risk 0.37cvss 5.7epss 0.00
Improper authorization vulnerability in semAddPublicDnsAddr in WifiSevice prior to SMR Jan-2023 Release 1 allows attackers to set custom DNS server without permission via binding WifiService.
- risk 0.36cvss 5.5epss 0.00
Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
- risk 0.36cvss 5.5epss 0.00
Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.
- risk 0.36cvss 5.5epss 0.00
Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
- risk 0.36cvss 5.5epss 0.00
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.
- risk 0.36cvss 5.5epss 0.00
Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
- risk 0.36cvss 5.5epss 0.00
Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
- risk 0.36cvss 5.5epss 0.00
Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.
- risk 0.36cvss 5.5epss 0.00
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.
- risk 0.36cvss 5.5epss 0.00
Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.6epss 0.00
Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
- risk 0.36cvss 5.5epss 0.00
Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.
Page 13 of 24