Vendor CVEs
Samsung Mobile
All CVEs
2,312 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42483 | Med | 0.41 | 6.3 | 0.00 | Dec 13, 2023 | A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system. | ||
| CVE-2023-42555 | Med | 0.41 | 6.3 | 0.00 | Nov 7, 2023 | Use of implicit intent for sensitive communication vulnerability in EasySetup prior to version 11.1.13 allows attackers to get the bluetooth address of user device. | ||
| CVE-2023-42534 | Med | 0.41 | 6.3 | 0.00 | Nov 7, 2023 | Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege. | ||
| CVE-2023-30671 | Med | 0.41 | 6.3 | 0.00 | Jul 6, 2023 | Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application. | ||
| CVE-2023-21492 | Med | 0.41 | 4.4 | 0.03 | KEV | May 4, 2023 | Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR. | |
| CVE-2023-21434 | Med | 0.41 | 6.2 | 0.13 | Feb 9, 2023 | Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page. | ||
| CVE-2021-25511 | Med | 0.41 | 6.3 | 0.00 | Dec 8, 2021 | An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability. | ||
| CVE-2021-25337 | Med | 0.41 | 4.4 | 0.03 | KEV | Mar 4, 2021 | Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files. | |
| CVE-2018-14856 | Med | 0.41 | 6.3 | 0.01 | Dec 17, 2018 | Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi) chip to cause the device driver to… | ||
| CVE-2018-14855 | Med | 0.41 | 6.3 | 0.01 | Dec 17, 2018 | Buffer overflow in dhd_bus_flow_ring_flush_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 allow an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device driver to perform invalid memory… | ||
| CVE-2018-14854 | Med | 0.41 | 6.3 | 0.01 | Dec 17, 2018 | Buffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device driver to… | ||
| CVE-2018-14852 | Med | 0.41 | 6.3 | 0.01 | Dec 17, 2018 | Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause invalid accesses to operating… | ||
| CVE-2026-21103 | Med | 0.40 | 6.1 | 0.00 | Sep 9, 2026 | Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege. | ||
| CVE-2026-21073 | Med | 0.40 | 6.1 | 0.00 | Aug 10, 2026 | Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. | ||
| CVE-2026-21063 | Med | 0.40 | 6.1 | 0.00 | Aug 10, 2026 | Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function. | ||
| CVE-2026-20994 | Med | 0.40 | 6.1 | 0.00 | Mar 16, 2026 | URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token. | ||
| CVE-2026-20978 | Med | 0.40 | 6.1 | 0.00 | Feb 4, 2026 | Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. | ||
| CVE-2025-58344 | Med | 0.40 | 6.2 | 0.00 | Feb 3, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation in a /proc/driver/unifi0/conn_log_event_burst_to_us write operation,… | ||
| CVE-2025-58342 | Med | 0.40 | 6.2 | 0.00 | Feb 3, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/uapsd write operation,… | ||
| CVE-2025-58341 | Med | 0.40 | 6.2 | 0.00 | Feb 3, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_cert_disable_ht_vht write… | ||
| CVE-2025-58340 | Med | 0.40 | 6.2 | 0.00 | Feb 3, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_delts write operation,… | ||
| CVE-2025-52516 | Med | 0.40 | 6.2 | 0.00 | Jan 5, 2026 | An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of service. | ||
| CVE-2025-21080 | Med | 0.40 | 6.2 | 0.00 | Dec 2, 2025 | Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege. | ||
| CVE-2025-21059 | Med | 0.40 | 6.2 | 0.00 | Oct 10, 2025 | Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health. | ||
| CVE-2025-21041 | Med | 0.40 | 6.2 | 0.00 | Sep 3, 2025 | Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information. | ||
| CVE-2023-21482 | Med | 0.40 | 6.1 | 0.00 | Sep 3, 2025 | Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to install package through Galaxy store before completion of Setup wizard. | ||
| CVE-2025-21013 | Med | 0.40 | 6.2 | 0.00 | Aug 6, 2025 | Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time. | ||
| CVE-2025-53082 | Med | 0.40 | 6.1 | 0.00 | Jul 29, 2025 | An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses. | ||
| CVE-2025-21004 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device. | ||
| CVE-2025-21002 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast. | ||
| CVE-2025-21001 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast. | ||
| CVE-2025-21000 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth. | ||
| CVE-2025-20997 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch. | ||
| CVE-2025-20981 | Med | 0.40 | 6.2 | 0.00 | Jun 4, 2025 | Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2025-20978 | Med | 0.40 | 6.2 | 0.00 | May 7, 2025 | Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege. | ||
| CVE-2025-20974 | Med | 0.40 | 6.1 | 0.00 | May 7, 2025 | Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation. | ||
| CVE-2025-20972 | Med | 0.40 | 6.2 | 0.00 | May 7, 2025 | Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration. | ||
| CVE-2025-20970 | Med | 0.40 | 6.2 | 0.00 | May 7, 2025 | Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to access image files with Bixby Vision privilege. | ||
| CVE-2025-20965 | Med | 0.40 | 6.2 | 0.00 | May 7, 2025 | Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data. | ||
| CVE-2025-20944 | Med | 0.40 | 6.2 | 0.00 | Apr 8, 2025 | Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory. | ||
| CVE-2025-20941 | Med | 0.40 | 6.2 | 0.00 | Apr 8, 2025 | Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device. | ||
| CVE-2025-20912 | Med | 0.40 | 6.2 | 0.00 | Mar 6, 2025 | Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch. | ||
| CVE-2025-20910 | Med | 0.40 | 6.2 | 0.00 | Mar 6, 2025 | Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery. | ||
| CVE-2024-45184 | Med | 0.40 | 6.2 | 0.00 | Oct 11, 2024 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, and Modem 5300. A USAT out-of-bounds write due to a heap buffer… | ||
| CVE-2024-34662 | Med | 0.40 | 6.2 | 0.00 | Oct 8, 2024 | Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors. | ||
| CVE-2024-34655 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager. | ||
| CVE-2024-34654 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege. | ||
| CVE-2024-34651 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files. | ||
| CVE-2024-34645 | Med | 0.40 | 6.1 | 0.00 | Sep 4, 2024 | Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications. | ||
| CVE-2024-34637 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background. |
- risk 0.41cvss 6.3epss 0.00
A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.
- risk 0.41cvss 6.3epss 0.00
Use of implicit intent for sensitive communication vulnerability in EasySetup prior to version 11.1.13 allows attackers to get the bluetooth address of user device.
- risk 0.41cvss 6.3epss 0.00
Improper input validation vulnerability in ChooserActivity prior to SMR Nov-2023 Release 1 allows local attackers to read arbitrary files with system privilege.
- risk 0.41cvss 6.3epss 0.00
Logic error in package installation via adb command prior to SMR Jul-2023 Release 1 allows local attackers to downgrade installed application.
- risk 0.41cvss 4.4epss 0.03
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
- risk 0.41cvss 6.2epss 0.13
Improper input validation vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to execute JavaScript by launching a web page.
- risk 0.41cvss 6.3epss 0.00
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.
- risk 0.41cvss 4.4epss 0.03
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
- risk 0.41cvss 6.3epss 0.01
Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi) chip to cause the device driver to…
- risk 0.41cvss 6.3epss 0.01
Buffer overflow in dhd_bus_flow_ring_flush_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 allow an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device driver to perform invalid memory…
- risk 0.41cvss 6.3epss 0.01
Buffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device driver to…
- risk 0.41cvss 6.3epss 0.01
Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause invalid accesses to operating…
- risk 0.40cvss 6.1epss 0.00
Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
- risk 0.40cvss 6.1epss 0.00
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.
- risk 0.40cvss 6.1epss 0.00
URL redirection in Samsung Account prior to version 15.5.01.1 allows local attackers to potentially get access token.
- risk 0.40cvss 6.1epss 0.00
Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
- risk 0.40cvss 6.2epss 0.00
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation in a /proc/driver/unifi0/conn_log_event_burst_to_us write operation,…
- risk 0.40cvss 6.2epss 0.00
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/uapsd write operation,…
- risk 0.40cvss 6.2epss 0.00
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_cert_disable_ht_vht write…
- risk 0.40cvss 6.2epss 0.00
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/send_delts write operation,…
- risk 0.40cvss 6.2epss 0.00
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. An invalid kernel address dereference in the issimian device driver leads to a denial of service.
- risk 0.40cvss 6.2epss 0.00
Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.
- risk 0.40cvss 6.2epss 0.00
Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health.
- risk 0.40cvss 6.2epss 0.00
Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.
- risk 0.40cvss 6.1epss 0.00
Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to install package through Galaxy store before completion of Setup wizard.
- risk 0.40cvss 6.2epss 0.00
Improper access control in SemSensorManager for Galaxy Watch prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information related to outdoor exercise and sleep time.
- risk 0.40cvss 6.1epss 0.00
An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.
- risk 0.40cvss 6.2epss 0.00
Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.
- risk 0.40cvss 6.2epss 0.00
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.
- risk 0.40cvss 6.2epss 0.00
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.
- risk 0.40cvss 6.2epss 0.00
Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.
- risk 0.40cvss 6.2epss 0.00
Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.
- risk 0.40cvss 6.2epss 0.00
Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.40cvss 6.2epss 0.00
Improper access control in PENUP prior to version 3.9.19.32 allows local attackers to access files with PENUP privilege.
- risk 0.40cvss 6.1epss 0.00
Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation.
- risk 0.40cvss 6.2epss 0.00
Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.
- risk 0.40cvss 6.2epss 0.00
Improper access control in Bixby Vision prior to version 3.8.1 in Android 13, 3.8.3 in Android 14, 3.8.21 in Android 15 allows local attackers to access image files with Bixby Vision privilege.
- risk 0.40cvss 6.2epss 0.00
Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.
- risk 0.40cvss 6.2epss 0.00
Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.
- risk 0.40cvss 6.2epss 0.00
Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.
- risk 0.40cvss 6.2epss 0.00
Incorrect default permission in DiagMonAgent prior to SMR Mar-2025 Release 1 allows local attackers to access data within Galaxy Watch.
- risk 0.40cvss 6.2epss 0.00
Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.
- risk 0.40cvss 6.2epss 0.00
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modems with chipset Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, Modem 5123, and Modem 5300. A USAT out-of-bounds write due to a heap buffer…
- risk 0.40cvss 6.2epss 0.00
Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors.
- risk 0.40cvss 6.2epss 0.00
Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.
- risk 0.40cvss 6.2epss 0.00
Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.
- risk 0.40cvss 6.2epss 0.00
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.
- risk 0.40cvss 6.2epss 0.00
Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.
Page 21 of 47