Android
CVEs (475)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21469 | Med | 0.26 | 4.0 | 0.00 | Sep 3, 2025 | Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action. | ||
| CVE-2025-21015 | Med | 0.26 | 4.0 | 0.00 | Aug 6, 2025 | Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege. | ||
| CVE-2025-20990 | Med | 0.26 | 4.0 | 0.00 | Aug 6, 2025 | Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier. | ||
| CVE-2025-21003 | Med | 0.26 | 4.0 | 0.00 | Jul 8, 2025 | Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2025-20993 | Med | 0.26 | 4.0 | 0.00 | Jun 4, 2025 | Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2025-20992 | Med | 0.26 | 4.0 | 0.00 | Jun 4, 2025 | Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory. | ||
| CVE-2025-20991 | Med | 0.26 | 4.0 | 0.00 | Jun 4, 2025 | Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable. | ||
| CVE-2025-20980 | Med | 0.26 | 4.0 | 0.00 | May 7, 2025 | Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption. | ||
| CVE-2025-20962 | Med | 0.26 | 4.0 | 0.00 | May 7, 2025 | Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position. | ||
| CVE-2025-20960 | Med | 0.26 | 4.0 | 0.00 | May 7, 2025 | Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api. | ||
| CVE-2025-20909 | Med | 0.26 | 4.0 | 0.00 | Mar 6, 2025 | Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2024-34680 | Med | 0.26 | 4.0 | 0.00 | Nov 6, 2024 | Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-34679 | Med | 0.26 | 4.0 | 0.00 | Nov 6, 2024 | Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege. | ||
| CVE-2024-34677 | Med | 0.26 | 4.0 | 0.00 | Nov 6, 2024 | Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate. | ||
| CVE-2024-34652 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage. | ||
| CVE-2024-34650 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel. | ||
| CVE-2024-34647 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license. | ||
| CVE-2024-34618 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information. | ||
| CVE-2024-34617 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application. | ||
| CVE-2024-34603 | Med | 0.26 | 4.0 | 0.00 | Jul 8, 2024 | Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data. |
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.
- risk 0.26cvss 4.0epss 0.00
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
- risk 0.26cvss 4.0epss 0.00
Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
- risk 0.26cvss 4.0epss 0.00
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.
- risk 0.26cvss 4.0epss 0.00
Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.
- risk 0.26cvss 4.0epss 0.00
Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.
- risk 0.26cvss 4.0epss 0.00
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
- risk 0.26cvss 4.0epss 0.00
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
- risk 0.26cvss 4.0epss 0.00
Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.
- risk 0.26cvss 4.0epss 0.00
Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.
- risk 0.26cvss 4.0epss 0.00
Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.
Page 21 of 24