Android
CVEs (475)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21441 | Hig | 0.48 | 7.4 | 0.00 | Feb 9, 2023 | Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code. | ||
| CVE-2025-20957 | Hig | 0.47 | 7.3 | 0.00 | May 7, 2025 | Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege. | ||
| CVE-2025-20903 | Hig | 0.47 | 7.3 | 0.00 | Mar 6, 2025 | Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-34614 | Hig | 0.47 | 7.3 | 0.00 | Aug 7, 2024 | Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code. | ||
| CVE-2024-34612 | Hig | 0.47 | 7.3 | 0.00 | Aug 7, 2024 | Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code. | ||
| CVE-2024-20878 | Hig | 0.47 | 7.3 | 0.00 | Jun 4, 2024 | Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code. | ||
| CVE-2024-20877 | Hig | 0.47 | 7.3 | 0.00 | Jun 4, 2024 | Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code. | ||
| CVE-2024-20849 | Hig | 0.47 | 7.3 | 0.00 | Apr 2, 2024 | Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 allows local attackers to execute arbitrary code. | ||
| CVE-2023-42568 | Hig | 0.47 | 7.3 | 0.00 | Dec 5, 2023 | Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege. | ||
| CVE-2023-42567 | Hig | 0.47 | 7.3 | 0.00 | Dec 5, 2023 | Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow. | ||
| CVE-2023-42566 | Hig | 0.47 | 7.3 | 0.00 | Dec 5, 2023 | Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code. | ||
| CVE-2023-42565 | Hig | 0.47 | 7.3 | 0.00 | Dec 5, 2023 | Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code. | ||
| CVE-2023-21420 | Hig | 0.47 | 7.3 | 0.00 | Feb 9, 2023 | Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution. | ||
| CVE-2025-21050 | Hig | 0.46 | 7.1 | 0.00 | Oct 10, 2025 | Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles. | ||
| CVE-2025-21006 | Hig | 0.46 | 7.0 | 0.00 | Jul 8, 2025 | Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory. | ||
| CVE-2025-20890 | Hig | 0.46 | 7.0 | 0.00 | Feb 4, 2025 | Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20888 | Hig | 0.46 | 7.0 | 0.00 | Feb 4, 2025 | Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20882 | Hig | 0.46 | 7.0 | 0.00 | Feb 4, 2025 | Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20881 | Hig | 0.46 | 7.0 | 0.00 | Feb 4, 2025 | Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability. | ||
| CVE-2024-49413 | Hig | 0.46 | 7.1 | 0.00 | Dec 3, 2024 | Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications. |
- risk 0.48cvss 7.4epss 0.00
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(11) and 3.5.2.23 in Android S(12) allows local attacker to access protected files via unused code.
- risk 0.47cvss 7.3epss 0.00
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.
- risk 0.47cvss 7.3epss 0.00
Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
- risk 0.47cvss 7.3epss 0.00
Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.
- risk 0.47cvss 7.3epss 0.00
Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.
- risk 0.47cvss 7.3epss 0.00
Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.
- risk 0.47cvss 7.3epss 0.00
Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.
- risk 0.47cvss 7.3epss 0.00
Out-of-bound Write vulnerability in chunk parsing implementation of libsdffextractor prior to SMR Apr-2023 Release 1 allows local attackers to execute arbitrary code.
- risk 0.47cvss 7.3epss 0.00
Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
- risk 0.47cvss 7.3epss 0.00
Improper size check vulnerability in softsimd prior to SMR Dec-2023 Release 1 allows stack-based buffer overflow.
- risk 0.47cvss 7.3epss 0.00
Out-of-bound write vulnerability in libsavsvc prior to SMR Dec-2023 Release 1 allows local attackers to execute arbitrary code.
- risk 0.47cvss 7.3epss 0.00
Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.
- risk 0.47cvss 7.3epss 0.00
Use of Externally-Controlled Format String vulnerabilities in STST TA prior to SMR Jan-2023 Release 1 allows arbitrary code execution.
- risk 0.46cvss 7.1epss 0.00
Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.
- risk 0.46cvss 7.0epss 0.00
Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.
- risk 0.46cvss 7.0epss 0.00
Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.
- risk 0.46cvss 7.0epss 0.00
Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.
- risk 0.46cvss 7.0epss 0.00
Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.
- risk 0.46cvss 7.0epss 0.00
Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.
- risk 0.46cvss 7.1epss 0.00
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.
Page 5 of 24