Android
CVEs (487)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30720 | Med | 0.31 | 4.7 | 0.00 | Sep 6, 2023 | PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access. | ||
| CVE-2023-30701 | Med | 0.31 | 4.7 | 0.00 | Aug 10, 2023 | PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access. | ||
| CVE-2023-21490 | Med | 0.31 | 4.7 | 0.00 | May 4, 2023 | Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager. | ||
| CVE-2026-21070 | Med | 0.30 | 4.6 | 0.00 | Aug 10, 2026 | Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. | ||
| CVE-2026-21060 | Med | 0.30 | 4.6 | 0.00 | Aug 10, 2026 | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2026-20974 | Med | 0.30 | 4.6 | 0.00 | Jan 9, 2026 | Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock. | ||
| CVE-2025-20884 | Med | 0.30 | 4.6 | 0.00 | Feb 4, 2025 | Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2025-20883 | Med | 0.30 | 4.6 | 0.00 | Feb 4, 2025 | Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2024-49402 | Med | 0.30 | 4.6 | 0.00 | Nov 6, 2024 | Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles. | ||
| CVE-2024-34674 | Med | 0.30 | 4.6 | 0.00 | Nov 6, 2024 | Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles. | ||
| CVE-2024-34653 | Med | 0.30 | 4.6 | 0.00 | Sep 4, 2024 | Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege. | ||
| CVE-2024-34642 | Med | 0.30 | 4.6 | 0.00 | Sep 4, 2024 | Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information. | ||
| CVE-2024-34639 | Med | 0.30 | 4.6 | 0.00 | Sep 4, 2024 | Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation. | ||
| CVE-2024-20882 | Med | 0.30 | 4.6 | 0.00 | Jun 4, 2024 | Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access. | ||
| CVE-2023-30714 | Med | 0.30 | 4.6 | 0.00 | Sep 6, 2023 | Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock. | ||
| CVE-2023-30708 | Med | 0.30 | 4.6 | 0.01 | Sep 6, 2023 | Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status. | ||
| CVE-2026-20991 | Med | 0.29 | 4.4 | 0.00 | Mar 16, 2026 | Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents. | ||
| CVE-2025-20958 | Med | 0.29 | 4.4 | 0.00 | May 7, 2025 | Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors. | ||
| CVE-2025-20942 | Med | 0.29 | 4.4 | 0.00 | Apr 8, 2025 | Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID. | ||
| CVE-2024-34676 | Med | 0.29 | 4.4 | 0.00 | Nov 6, 2024 | Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability. |
- risk 0.31cvss 4.7epss 0.00
PendingIntent hijacking in LmsAssemblyTrackerCTC prior to SMR Sep-2023 Release 1 allows local attacker to gain arbitrary file access.
- risk 0.31cvss 4.7epss 0.00
PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.
- risk 0.31cvss 4.7epss 0.00
Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.
- risk 0.30cvss 4.6epss 0.00
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
- risk 0.30cvss 4.6epss 0.00
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.
- risk 0.30cvss 4.6epss 0.00
Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.
- risk 0.30cvss 4.6epss 0.00
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
- risk 0.30cvss 4.6epss 0.00
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
- risk 0.30cvss 4.6epss 0.00
Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.
- risk 0.30cvss 4.6epss 0.00
Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.
- risk 0.30cvss 4.6epss 0.01
Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.
- risk 0.29cvss 4.4epss 0.00
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
- risk 0.29cvss 4.4epss 0.00
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.
- risk 0.29cvss 4.4epss 0.00
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.
- risk 0.29cvss 4.4epss 0.00
Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability.
Page 18 of 25