Android
CVEs (475)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30715 | Med | 0.26 | 4.0 | 0.00 | Sep 6, 2023 | Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission. | ||
| CVE-2023-30711 | Med | 0.26 | 4.0 | 0.00 | Sep 6, 2023 | Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider. | ||
| CVE-2023-30707 | Med | 0.26 | 4.0 | 0.00 | Sep 6, 2023 | Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege. | ||
| CVE-2023-21495 | Med | 0.26 | 4.0 | 0.00 | May 4, 2023 | Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set. | ||
| CVE-2023-21461 | Med | 0.26 | 4.0 | 0.00 | Mar 16, 2023 | Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity. | ||
| CVE-2023-21449 | Med | 0.26 | 4.0 | 0.00 | Mar 16, 2023 | Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission. | ||
| CVE-2023-21442 | Med | 0.26 | 4.0 | 0.00 | Feb 9, 2023 | Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information. | ||
| CVE-2023-21437 | Med | 0.26 | 4.0 | 0.00 | Feb 9, 2023 | Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast. | ||
| CVE-2023-21429 | Med | 0.26 | 4.0 | 0.00 | Feb 9, 2023 | Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID. | ||
| CVE-2023-21428 | Med | 0.26 | 4.0 | 0.00 | Feb 9, 2023 | Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code. | ||
| CVE-2026-21027 | Low | 0.21 | 3.3 | 0.00 | Jun 5, 2026 | Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function. | ||
| CVE-2026-21012 | Low | 0.21 | 3.3 | 0.00 | Apr 13, 2026 | External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege. | ||
| CVE-2026-20992 | Low | 0.21 | 3.3 | 0.00 | Mar 16, 2026 | Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application. | ||
| CVE-2026-20972 | Low | 0.21 | 3.3 | 0.00 | Jan 9, 2026 | Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB. | ||
| CVE-2024-34640 | Low | 0.21 | 3.3 | 0.00 | Sep 4, 2024 | Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration. | ||
| CVE-2024-34602 | Low | 0.21 | 3.3 | 0.00 | Jul 8, 2024 | Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-20836 | Low | 0.21 | 3.3 | 0.00 | Mar 5, 2024 | Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory. | ||
| CVE-2024-20834 | Low | 0.21 | 3.3 | 0.00 | Mar 5, 2024 | The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission. | ||
| CVE-2024-20810 | Low | 0.21 | 3.3 | 0.00 | Feb 6, 2024 | Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20805 | Low | 0.21 | 3.3 | 0.00 | Jan 4, 2024 | Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file. |
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.
- risk 0.26cvss 4.0epss 0.00
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
- risk 0.26cvss 4.0epss 0.00
Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in Knox Enrollment Service prior to SMR May-2023 Release 1 allow attacker install KSP app when device admin is set.
- risk 0.26cvss 4.0epss 0.00
Improper authorization vulnerability in AutoPowerOnOffConfirmDialog in Settings prior to SMR Mar-2023 Release 1 allows local attacker to turn device off via unprotected activity.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in Call application prior to SMR Mar-2023 Release 1 allows local attackers to access sensitive information without proper permission.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in Runestone application prior to version 2.9.09.003 in Android R(11) and 3.2.01.007 in Android S(12) allows local attackers to get device location information.
- risk 0.26cvss 4.0epss 0.00
Improper access control vulnerability in Phone application prior to SMR Feb-2023 Release 1 allows local attackers to access sensitive information via implicit broadcast.
- risk 0.26cvss 4.0epss 0.00
Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
- risk 0.26cvss 4.0epss 0.00
Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.
- risk 0.21cvss 3.3epss 0.00
Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.
- risk 0.21cvss 3.3epss 0.00
External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.
- risk 0.21cvss 3.3epss 0.00
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
- risk 0.21cvss 3.3epss 0.00
Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
- risk 0.21cvss 3.3epss 0.00
Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.
- risk 0.21cvss 3.3epss 0.00
Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.
- risk 0.21cvss 3.3epss 0.00
The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.
- risk 0.21cvss 3.3epss 0.00
Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.21cvss 3.3epss 0.00
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
Page 23 of 24