Android
CVEs (487)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-20960 | Med | 0.26 | 4.0 | 0.00 | May 7, 2025 | Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api. | ||
| CVE-2025-20909 | Med | 0.26 | 4.0 | 0.00 | Mar 6, 2025 | Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2024-34680 | Med | 0.26 | 4.0 | 0.00 | Nov 6, 2024 | Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-34679 | Med | 0.26 | 4.0 | 0.00 | Nov 6, 2024 | Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege. | ||
| CVE-2024-34677 | Med | 0.26 | 4.0 | 0.00 | Nov 6, 2024 | Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate. | ||
| CVE-2024-34652 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage. | ||
| CVE-2024-34650 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel. | ||
| CVE-2024-34647 | Med | 0.26 | 4.0 | 0.00 | Sep 4, 2024 | Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license. | ||
| CVE-2024-34618 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information. | ||
| CVE-2024-34617 | Med | 0.26 | 4.0 | 0.00 | Aug 7, 2024 | Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application. | ||
| CVE-2024-34603 | Med | 0.26 | 4.0 | 0.00 | Jul 8, 2024 | Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data. | ||
| CVE-2024-34583 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier. | ||
| CVE-2024-20900 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication. | ||
| CVE-2024-20899 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20898 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20897 | Med | 0.26 | 4.0 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20879 | Med | 0.26 | 4.0 | 0.00 | Jun 4, 2024 | Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory. | ||
| CVE-2024-20875 | Med | 0.26 | 4.0 | 0.00 | Jun 4, 2024 | Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files. | ||
| CVE-2024-20860 | Med | 0.26 | 4.0 | 0.00 | May 7, 2024 | Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission. | ||
| CVE-2024-20858 | Med | 0.26 | 4.0 | 0.00 | May 7, 2024 | Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application. |
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.
- risk 0.26cvss 4.0epss 0.00
Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.
- risk 0.26cvss 4.0epss 0.00
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
- risk 0.26cvss 4.0epss 0.00
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
- risk 0.26cvss 4.0epss 0.00
Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.
- risk 0.26cvss 4.0epss 0.00
Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.
- risk 0.26cvss 4.0epss 0.00
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.
- risk 0.26cvss 4.0epss 0.00
Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.
- risk 0.26cvss 4.0epss 0.00
Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.
- risk 0.26cvss 4.0epss 0.00
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.26cvss 4.0epss 0.00
Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.
- risk 0.26cvss 4.0epss 0.00
Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files.
- risk 0.26cvss 4.0epss 0.00
Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in setCocktailHostCallbacks of CocktailBarService prior to SMR May-2024 Release 1 allows local attackers to access information of current application.
Page 22 of 25