Android
CVEs (475)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-20988 | Med | 0.36 | 5.5 | 0.00 | Jun 4, 2025 | Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory. | ||
| CVE-2025-20985 | Med | 0.36 | 5.5 | 0.00 | Jun 4, 2025 | Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items. | ||
| CVE-2025-20961 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege. | ||
| CVE-2025-20955 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images. | ||
| CVE-2025-20954 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20952 | Med | 0.36 | 5.5 | 0.00 | Apr 9, 2025 | Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege. | ||
| CVE-2025-20948 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory. | ||
| CVE-2025-20947 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20938 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts. | ||
| CVE-2025-20934 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege. | ||
| CVE-2024-34594 | Med | 0.36 | 5.5 | 0.00 | Jul 2, 2024 | Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address. | ||
| CVE-2024-20896 | Med | 0.36 | 5.5 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20864 | Med | 0.36 | 5.5 | 0.00 | May 7, 2024 | Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources. | ||
| CVE-2024-20859 | Med | 0.36 | 5.5 | 0.00 | May 7, 2024 | Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege. | ||
| CVE-2024-20843 | Med | 0.36 | 5.6 | 0.00 | Apr 2, 2024 | Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code. | ||
| CVE-2023-42557 | Med | 0.36 | 5.6 | 0.00 | Dec 5, 2023 | Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code. | ||
| CVE-2023-42527 | Med | 0.36 | 5.6 | 0.00 | Nov 7, 2023 | Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information. | ||
| CVE-2023-30732 | Med | 0.36 | 5.5 | 0.00 | Oct 4, 2023 | Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number. | ||
| CVE-2023-30698 | Med | 0.36 | 5.5 | 0.00 | Aug 10, 2023 | Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege. | ||
| CVE-2023-21504 | Med | 0.36 | 5.6 | 0.01 | May 4, 2023 | Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access. |
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items.
- risk 0.36cvss 5.5epss 0.00
Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.
- risk 0.36cvss 5.5epss 0.00
Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.
- risk 0.36cvss 5.5epss 0.00
Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.
- risk 0.36cvss 5.5epss 0.00
Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.
- risk 0.36cvss 5.5epss 0.00
Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.36cvss 5.5epss 0.00
Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.
- risk 0.36cvss 5.5epss 0.00
Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.
- risk 0.36cvss 5.6epss 0.00
Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code.
- risk 0.36cvss 5.6epss 0.00
Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.
- risk 0.36cvss 5.6epss 0.00
Improper input validation vulnerability in ProcessWriteFile of libsec-ril prior to SMR Nov-2023 Release 1 allows local attackers to expose sensitive information.
- risk 0.36cvss 5.5epss 0.00
Improper access control in system property prior to SMR Oct-2023 Release 1 allows local attacker to get CPU serial number.
- risk 0.36cvss 5.5epss 0.00
Improper access control vulnerability in TelephonyUI prior to SMR Aug-2023 Release 1 allows local attacker to connect BLE without privilege.
- risk 0.36cvss 5.6epss 0.01
Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.
Page 14 of 24