Samsung Android
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Samsung Android.
By the Year
In 2025 there have been 0 vulnerabilities in Samsung Android. Last year, in 2024 Android had 95 security vulnerabilities published. Right now, Android is on track to have less security vulnerabilities in 2025 than it did last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2025 | 0 | 0.00 |
2024 | 95 | 5.89 |
2023 | 154 | 6.24 |
2022 | 0 | 0.00 |
2021 | 0 | 0.00 |
2020 | 0 | 0.00 |
2019 | 0 | 0.00 |
2018 | 0 | 0.00 |
It may take a day or so for new Android vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Samsung Android Security Vulnerabilities
Modem IpcProtocol DoS via Input Validation Flaw
CVE-2024-34673
5.5 - Medium
- November 06, 2024
Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.
Samsung Settings WiFi Password Exposure
CVE-2024-34682
2.4 - Low
- November 06, 2024
Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi password in Maintenance Mode.
Samsung Contacts Profile Access Control Bypass
CVE-2024-34674
4.6 - Medium
- November 06, 2024
Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.
Dex Mode Access Control Bypass
CVE-2024-34675
4.6 - Medium
- November 06, 2024
Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to unlocked screen.
Samsung libsubextractor OOB Write
CVE-2024-34676
7.3 - High
- November 06, 2024
Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability.
Memory Corruption
System UI Sensitive Info Leak in Samsung SMR
CVE-2024-34677
3.3 - Low
- November 06, 2024
Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.
Insecure Storage of Sensitive Information
Samsung libsapeextractor OOB Write
CVE-2024-34678
7.8 - High
- November 06, 2024
Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.
Memory Corruption
Crane Privilege Escalation via Default Permissions
CVE-2024-34679
7.1 - High
- November 06, 2024
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.
Incorrect Default Permissions
WlanTest Implicit Intent Info Leak
CVE-2024-34680
5.5 - Medium
- November 06, 2024
Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.
Samsung Settings Suggestion Privilege Escalation
CVE-2024-49401
7.1 - High
- November 06, 2024
Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities.
Dressroom Profile Data Leak via Input Validation Flaw
CVE-2024-49402
4.6 - Medium
- November 06, 2024
Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.
Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14
CVE-2024-34662
7.8 - High
- October 08, 2024
Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors.
Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1
CVE-2024-34665
8.8 - High
- October 08, 2024
Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
Memory Corruption
Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1
CVE-2024-34666
8.8 - High
- October 08, 2024
Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
Memory Corruption
Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1
CVE-2024-34667
8.8 - High
- October 08, 2024
Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
Memory Corruption
Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1
CVE-2024-34668
8.8 - High
- October 08, 2024
Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
Memory Corruption
Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1
CVE-2024-34669
8.8 - High
- October 08, 2024
Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
Memory Corruption
Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1
CVE-2024-34641
3.3 - Low
- September 04, 2024
Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.
Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14
CVE-2024-34637
5.5 - Medium
- September 04, 2024
Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.
Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1
CVE-2024-34638
7.1 - High
- September 04, 2024
Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.
Improper Handling of Exceptional Conditions
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1
CVE-2024-34639
4.6 - Medium
- September 04, 2024
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
Improper Handling of Exceptional Conditions
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1
CVE-2024-34640
3.3 - Low
- September 04, 2024
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1
CVE-2024-34642
4.6 - Medium
- September 04, 2024
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
AuthZ
Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1
CVE-2024-34643
5.5 - Medium
- September 04, 2024
Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.
Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1
CVE-2024-34644
5.5 - Medium
- September 04, 2024
Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for triggering this vulnerability.
Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1
CVE-2024-34645
4.6 - Medium
- September 04, 2024
Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.
Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1
CVE-2024-34646
5.5 - Medium
- September 04, 2024
Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.
Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1
CVE-2024-34647
5.5 - Medium
- September 04, 2024
Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1
CVE-2024-34648
5.5 - Medium
- September 04, 2024
Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.
Incorrect Default Permissions
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1
CVE-2024-34649
2.4 - Low
- September 04, 2024
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.
Path Traversal in My Files prior to SMR Sep-2024 Release 1
CVE-2024-34653
4.6 - Medium
- September 04, 2024
Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.
Directory traversal
Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1
CVE-2024-34654
5.5 - Medium
- September 04, 2024
Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.
Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1
CVE-2024-34655
5.5 - Medium
- September 04, 2024
Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1
CVE-2024-34650
3.3 - Low
- September 04, 2024
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
AuthZ
Improper authorization in My Files prior to SMR Sep-2024 Release 1
CVE-2024-34651
5.5 - Medium
- September 04, 2024
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
AuthZ
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1
CVE-2024-34652
3.3 - Low
- September 04, 2024
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
AuthZ
Improper access control in LedCoverService prior to SMR Aug-2024 Release 1
CVE-2024-34604
5.5 - Medium
- August 07, 2024
Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1
CVE-2024-34605
5.5 - Medium
- August 07, 2024
Improper access control in SamsungHealthService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1
CVE-2024-34606
5.5 - Medium
- August 07, 2024
Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1
CVE-2024-34607
5.5 - Medium
- August 07, 2024
Improper access control in SamsungNotesService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1
CVE-2024-34608
5.5 - Medium
- August 07, 2024
Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1
CVE-2024-34609
5.5 - Medium
- August 07, 2024
Improper access control in VoiceNoteService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1
CVE-2024-34610
5.5 - Medium
- August 07, 2024
Improper access control in ExtControlDeviceService prior to SMR Aug-2024 Release 1 allows local attackers to access protected data.
Improper access control in KnoxService prior to SMR Aug-2024 Release 1
CVE-2024-34611
5.5 - Medium
- August 07, 2024
Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.
Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1
CVE-2024-34612
7.8 - High
- August 07, 2024
Out-of-bound write in libcodec2secmp4vdec.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.
Memory Corruption
Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1
CVE-2024-34614
7.8 - High
- August 07, 2024
Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to execute arbitrary code.
Memory Corruption
Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1
CVE-2024-34615
7.8 - High
- August 07, 2024
Out-of-bound write in libsmat.so prior to SMR Aug-2024 Release 1 allows local attackers to cause memory corruption.
Memory Corruption
Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1
CVE-2024-34616
5.5 - Medium
- August 07, 2024
Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.
Incorrect Default Permissions
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1
CVE-2024-34617
3.3 - Low
- August 07, 2024
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.
Incorrect Default Permissions
Improper access control in System property prior to SMR Aug-2024 Release 1
CVE-2024-34618
3.3 - Low
- August 07, 2024
Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.
Improper input validation in librtp.so prior to SMR Aug-2024 Release 1
CVE-2024-34619
8.8 - High
- August 07, 2024
Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1
CVE-2024-34620
7.8 - High
- August 07, 2024
Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.
Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1
CVE-2024-34602
5.5 - Medium
- July 08, 2024
Use of implicit intent for sensitive communication in Samsung Messages prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.
Improper access control in Samsung Message prior to SMR Jul-2024 Release 1
CVE-2024-34603
5.5 - Medium
- July 08, 2024
Improper access control in Samsung Message prior to SMR Jul-2024 Release 1 allows local attackers to access location data.
Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1
CVE-2024-34587
6.8 - Medium
- July 02, 2024
Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1
CVE-2024-34591
4.3 - Medium
- July 02, 2024
Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Improper input validation?in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1
CVE-2024-34590
4.3 - Medium
- July 02, 2024
Improper input validation?in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1
CVE-2024-34595
7.8 - High
- July 02, 2024
Improper access control in clickAdapterItem of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.
Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1
CVE-2024-34594
5.5 - Medium
- July 02, 2024
Exposure of sensitive information in proc file system prior to SMR Jul-2024 Release 1 allows local attackers to read kernel memory address.
Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1
CVE-2024-34593
8.8 - High
- July 02, 2024
Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1
CVE-2024-34592
4.3 - Medium
- July 02, 2024
Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1
CVE-2024-20897
5.5 - Medium
- July 02, 2024
Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1
CVE-2024-20896
5.5 - Medium
- July 02, 2024
Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
Improper access control in Dar service prior to SMR Jul-2024 Release 1
CVE-2024-20895
5.5 - Medium
- July 02, 2024
Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.
Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1
CVE-2024-20894
4.3 - Medium
- July 02, 2024
Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.
Improper Handling of Exceptional Conditions
Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1
CVE-2024-20893
7.8 - High
- July 02, 2024
Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.
Memory Corruption
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors
CVE-2024-20892
7.8 - High
- July 02, 2024
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.
Improper Verification of Cryptographic Signature
Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1
CVE-2024-20891
7.8 - High
- July 02, 2024
Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.
Improper authentication in BLE prior to SMR Jul-2024 Release 1
CVE-2024-20889
4.3 - Medium
- July 02, 2024
Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.
authentification
Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities
CVE-2024-20888
7.8 - High
- July 02, 2024
Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1
CVE-2024-34589
6.5 - Medium
- July 02, 2024
Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Improper input validation?in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1
CVE-2024-34588
6.5 - Medium
- July 02, 2024
Improper input validation?in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Improper input validation in BLE prior to SMR Jul-2024 Release 1
CVE-2024-20890
8.8 - High
- July 02, 2024
Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.
authentification
Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1
CVE-2024-34586
3.3 - Low
- July 02, 2024
Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.
Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1
CVE-2024-34585
7.8 - High
- July 02, 2024
Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.
Improper access control in system property prior to SMR Jul-2024 Release 1
CVE-2024-34583
3.3 - Low
- July 02, 2024
Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.
Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1
CVE-2024-20901
7.8 - High
- July 02, 2024
Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.
Memory Corruption
Improper authentication in MTP application prior to SMR Jul-2024 Release 1
CVE-2024-20900
3.3 - Low
- July 02, 2024
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
authentification
Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1
CVE-2024-20899
5.5 - Medium
- July 02, 2024
Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1
CVE-2024-20898
5.5 - Medium
- July 02, 2024
Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1
CVE-2024-20817
7.8 - High
- February 06, 2024
Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
Memory Corruption
Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1
CVE-2024-20812
7.8 - High
- February 06, 2024
Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.
Memory Corruption
Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1
CVE-2024-20811
3.3 - Low
- February 06, 2024
Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.
Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1
CVE-2024-20810
3.3 - Low
- February 06, 2024
Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.
Clickjacking
Improper input validation in bootloader prior to SMR Feb-2024 Release 1
CVE-2024-20820
7.1 - High
- February 06, 2024
Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.
Out-of-bounds Read
Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1
CVE-2024-20819
7.8 - High
- February 06, 2024
Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
Memory Corruption
Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1
CVE-2024-20818
7.8 - High
- February 06, 2024
Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.
Memory Corruption
Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1
CVE-2024-20816
6.5 - Medium
- February 06, 2024
Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
authentification
Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1
CVE-2024-20815
6.5 - Medium
- February 06, 2024
Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
authentification
Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1
CVE-2024-20814
5.5 - Medium
- February 06, 2024
Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.
Out-of-bounds Read
Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1
CVE-2024-20813
7.8 - High
- February 06, 2024
Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.
Memory Corruption
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1
CVE-2024-20803
6.5 - Medium
- January 04, 2024
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
authentification
Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13
CVE-2024-20804
5.5 - Medium
- January 04, 2024
Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
Directory traversal
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13
CVE-2024-20805
5.5 - Medium
- January 04, 2024
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
Directory traversal
Improper access control in Notification service prior to SMR Jan-2024 Release 1
CVE-2024-20806
5.5 - Medium
- January 04, 2024
Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.
Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1
CVE-2023-42562
7.8 - High
- December 05, 2023
Integer overflow vulnerability in detectionFindFaceSupportMultiInstance of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
Integer Overflow or Wraparound
Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1
CVE-2023-42563
7.8 - High
- December 05, 2023
Integer overflow vulnerability in landmarkCopyImageToNative of libFacePreProcessingjni.camera.samsung.so prior to SMR Dec-2023 Release 1 allows attacker to trigger heap overflow.
Integer Overflow or Wraparound
Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1
CVE-2023-42564
5.5 - Medium
- December 05, 2023
Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1
CVE-2023-42565
6.7 - Medium
- December 05, 2023
Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.
Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1
CVE-2023-42568
4.4 - Medium
- December 05, 2023
Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Samsung Android or by Samsung? Click the Watch button to subscribe.