Android
CVEs (475)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21435 | Med | 0.29 | 4.4 | 0.00 | Feb 9, 2023 | Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log. | ||
| CVE-2023-21430 | Med | 0.29 | 4.4 | 0.00 | Feb 9, 2023 | An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault. | ||
| CVE-2025-58480 | Med | 0.28 | 4.3 | 0.00 | Dec 2, 2025 | Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory. | ||
| CVE-2025-58479 | Med | 0.28 | 4.3 | 0.00 | Dec 2, 2025 | Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory. | ||
| CVE-2025-58478 | Med | 0.28 | 4.3 | 0.00 | Dec 2, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory. | ||
| CVE-2025-58477 | Med | 0.28 | 4.3 | 0.00 | Dec 2, 2025 | Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory. | ||
| CVE-2025-21075 | Med | 0.28 | 4.3 | 0.00 | Nov 5, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory. | ||
| CVE-2025-21074 | Med | 0.28 | 4.3 | 0.00 | Nov 5, 2025 | Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory. | ||
| CVE-2025-21055 | Med | 0.28 | 4.3 | 0.00 | Oct 10, 2025 | Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory. | ||
| CVE-2025-21030 | Med | 0.28 | 4.3 | 0.00 | Sep 3, 2025 | Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background. | ||
| CVE-2025-21014 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2025 | Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2024-49411 | Med | 0.28 | 4.3 | 0.00 | Dec 3, 2024 | Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege. | ||
| CVE-2024-20894 | Med | 0.28 | 4.3 | 0.00 | Jul 2, 2024 | Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-20856 | Med | 0.28 | 4.3 | 0.00 | May 7, 2024 | Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario. | ||
| CVE-2023-30685 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2023 | Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode. | ||
| CVE-2023-30684 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2023 | Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission. | ||
| CVE-2023-30683 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2023 | Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission. | ||
| CVE-2023-30682 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2023 | Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission. | ||
| CVE-2023-30641 | Med | 0.28 | 4.3 | 0.00 | Jul 6, 2023 | Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data. | ||
| CVE-2023-30640 | Med | 0.28 | 4.3 | 0.00 | Jul 6, 2023 | Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration. |
- risk 0.29cvss 4.4epss 0.00
Exposure of Sensitive Information vulnerability in Fingerprint TA prior to SMR Feb-2023 Release 1 allows attackers to access the memory address information via log.
- risk 0.29cvss 4.4epss 0.00
An out-of-bound read vulnerability in mapToBuffer function in libSDKRecognitionText.spensdk.samsung.so library prior to SMR JAN-2023 Release 1 allows attacker to cause memory access fault.
- risk 0.28cvss 4.3epss 0.00
Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.
- risk 0.28cvss 4.3epss 0.00
Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.
- risk 0.28cvss 4.3epss 0.00
Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background.
- risk 0.28cvss 4.3epss 0.00
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.28cvss 4.3epss 0.00
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
- risk 0.28cvss 4.3epss 0.00
Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.
- risk 0.28cvss 4.3epss 0.00
Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.
- risk 0.28cvss 4.3epss 0.00
Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
- risk 0.28cvss 4.3epss 0.00
Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.
- risk 0.28cvss 4.3epss 0.00
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.
- risk 0.28cvss 4.3epss 0.00
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.
- risk 0.28cvss 4.3epss 0.00
Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.
- risk 0.28cvss 4.3epss 0.00
Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.
Page 19 of 24