Android
CVEs (487)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-21030 | Med | 0.28 | 4.3 | 0.00 | Sep 3, 2025 | Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background. | ||
| CVE-2025-21014 | Med | 0.28 | 4.3 | 0.00 | Aug 6, 2025 | Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2024-49411 | Med | 0.28 | 4.3 | 0.00 | Dec 3, 2024 | Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege. | ||
| CVE-2024-20894 | Med | 0.28 | 4.3 | 0.00 | Jul 2, 2024 | Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-20856 | Med | 0.28 | 4.3 | 0.00 | May 7, 2024 | Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario. | ||
| CVE-2023-30685 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2023 | Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode. | ||
| CVE-2023-30684 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2023 | Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission. | ||
| CVE-2023-30683 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2023 | Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission. | ||
| CVE-2023-30682 | Med | 0.28 | 4.3 | 0.00 | Aug 10, 2023 | Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission. | ||
| CVE-2023-30641 | Med | 0.28 | 4.3 | 0.00 | Jul 6, 2023 | Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data. | ||
| CVE-2023-30640 | Med | 0.28 | 4.3 | 0.00 | Jul 6, 2023 | Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration. | ||
| CVE-2023-21426 | Med | 0.28 | 4.3 | 0.00 | Feb 9, 2023 | Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN. | ||
| CVE-2023-21425 | Med | 0.28 | 4.3 | 0.00 | Feb 9, 2023 | Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2025-58476 | Med | 0.27 | 4.2 | 0.00 | Dec 2, 2025 | Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory. | ||
| CVE-2025-20999 | Med | 0.27 | 4.1 | 0.00 | Jul 8, 2025 | Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password. | ||
| CVE-2025-20886 | Med | 0.27 | 4.1 | 0.00 | Feb 4, 2025 | Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key. | ||
| CVE-2024-34673 | Med | 0.27 | 4.1 | 0.00 | Nov 6, 2024 | Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service. | ||
| CVE-2024-20873 | Med | 0.27 | 4.2 | 0.00 | Jun 4, 2024 | Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2024-20842 | Med | 0.27 | 4.2 | 0.00 | Apr 2, 2024 | Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory. | ||
| CVE-2024-20833 | Med | 0.27 | 4.1 | 0.00 | Mar 5, 2024 | Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption. |
- risk 0.28cvss 4.3epss 0.00
Improper handling of insufficient permission in AppPrelaunchManagerService prior to SMR Sep-2025 Release 1 in Chinese Android 15 allows local attackers to execute arbitrary application in the background.
- risk 0.28cvss 4.3epss 0.00
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.28cvss 4.3epss 0.00
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
- risk 0.28cvss 4.3epss 0.00
Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.
- risk 0.28cvss 4.3epss 0.00
Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.
- risk 0.28cvss 4.3epss 0.00
Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
- risk 0.28cvss 4.3epss 0.00
Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.
- risk 0.28cvss 4.3epss 0.00
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.
- risk 0.28cvss 4.3epss 0.00
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.
- risk 0.28cvss 4.3epss 0.00
Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.
- risk 0.28cvss 4.3epss 0.00
Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.
- risk 0.28cvss 4.3epss 0.00
Hardcoded AES key to encrypt cardemulation PINs in NFC prior to SMR Jan-2023 Release 1 allows attackers to access cardemulation PIN.
- risk 0.28cvss 4.3epss 0.00
Improper access control vulnerability in telecom application prior to SMR JAN-2023 Release 1 allows local attackers to get sensitive information.
- risk 0.27cvss 4.2epss 0.00
Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.
- risk 0.27cvss 4.1epss 0.00
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.
- risk 0.27cvss 4.1epss 0.00
Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.
- risk 0.27cvss 4.1epss 0.00
Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.
- risk 0.27cvss 4.2epss 0.00
Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.27cvss 4.2epss 0.00
Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
- risk 0.27cvss 4.1epss 0.00
Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.
Page 20 of 25