Android
CVEs (475)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-34642 | Med | 0.30 | 4.6 | 0.00 | Sep 4, 2024 | Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information. | ||
| CVE-2024-34639 | Med | 0.30 | 4.6 | 0.00 | Sep 4, 2024 | Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation. | ||
| CVE-2024-20882 | Med | 0.30 | 4.6 | 0.00 | Jun 4, 2024 | Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access. | ||
| CVE-2023-30714 | Med | 0.30 | 4.6 | 0.00 | Sep 6, 2023 | Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock. | ||
| CVE-2023-30708 | Med | 0.30 | 4.6 | 0.01 | Sep 6, 2023 | Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status. | ||
| CVE-2026-20991 | Med | 0.29 | 4.4 | 0.00 | Mar 16, 2026 | Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents. | ||
| CVE-2025-20958 | Med | 0.29 | 4.4 | 0.00 | May 7, 2025 | Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors. | ||
| CVE-2025-20942 | Med | 0.29 | 4.4 | 0.00 | Apr 8, 2025 | Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID. | ||
| CVE-2024-34676 | Med | 0.29 | 4.4 | 0.00 | Nov 6, 2024 | Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-34644 | Med | 0.29 | 4.4 | 0.00 | Sep 4, 2024 | Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-34643 | Med | 0.29 | 4.4 | 0.00 | Sep 4, 2024 | Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-20820 | Med | 0.29 | 4.4 | 0.00 | Feb 6, 2024 | Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read. | ||
| CVE-2023-30721 | Med | 0.29 | 4.4 | 0.00 | Sep 6, 2023 | Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log. | ||
| CVE-2023-30697 | Med | 0.29 | 4.4 | 0.00 | Aug 10, 2023 | An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write. | ||
| CVE-2023-30696 | Med | 0.29 | 4.4 | 0.00 | Aug 10, 2023 | An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write. | ||
| CVE-2023-30681 | Med | 0.29 | 4.4 | 0.00 | Aug 10, 2023 | An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write. | ||
| CVE-2023-30665 | Med | 0.29 | 4.4 | 0.00 | Jul 6, 2023 | Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read. | ||
| CVE-2023-21497 | Med | 0.29 | 4.4 | 0.00 | May 4, 2023 | Use of externally-controlled format string vulnerability in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the memory address. | ||
| CVE-2023-21488 | Med | 0.29 | 4.4 | 0.00 | May 4, 2023 | Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips. | ||
| CVE-2023-21460 | Med | 0.29 | 4.4 | 0.00 | Mar 16, 2023 | Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting. |
- risk 0.30cvss 4.6epss 0.00
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
- risk 0.30cvss 4.6epss 0.00
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
- risk 0.30cvss 4.6epss 0.00
Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.
- risk 0.30cvss 4.6epss 0.00
Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.
- risk 0.30cvss 4.6epss 0.01
Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.
- risk 0.29cvss 4.4epss 0.00
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
- risk 0.29cvss 4.4epss 0.00
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.
- risk 0.29cvss 4.4epss 0.00
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.
- risk 0.29cvss 4.4epss 0.00
Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability.
- risk 0.29cvss 4.4epss 0.00
Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.
- risk 0.29cvss 4.4epss 0.00
Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.
- risk 0.29cvss 4.4epss 0.00
Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.
- risk 0.29cvss 4.4epss 0.00
Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.
- risk 0.29cvss 4.4epss 0.00
An improper input validation in IpcTxCfgSetSimlockPayload in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
- risk 0.29cvss 4.4epss 0.00
An improper input validation in IpcTxGetVerifyAkey in libsec-ril prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
- risk 0.29cvss 4.4epss 0.00
An improper input validation vulnerability within initialize function in HAL VaultKeeper prior to SMR Aug-2023 Release 1 allows attacker to cause out-of-bounds write.
- risk 0.29cvss 4.4epss 0.00
Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.
- risk 0.29cvss 4.4epss 0.00
Use of externally-controlled format string vulnerability in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the memory address.
- risk 0.29cvss 4.4epss 0.00
Improper access control vulnerablility in Tips prior to SMR May-2023 Release 1 allows local attackers to launch arbitrary activity in Tips.
- risk 0.29cvss 4.4epss 0.00
Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
Page 18 of 24