← Back

Android

android

Vendor: Samsung • 465 CVEs

CVEs (465)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Android
Jun 17, 2026
Dec 3, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
1Samsung
1Android
Jun 17, 2026
Dec 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
2.4 LOW· v3
N/A· v2
Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi password in Maintenance Mode.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to unlocked screen.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.
1Samsung
1Android
Jun 17, 2026
Nov 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.
1Samsung
1Android
Jun 17, 2026
Oct 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this v...Show more
Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.Show less
1Samsung
1Android
Jun 17, 2026
Oct 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vu...Show more
Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.Show less
1Samsung
1Android
Jun 17, 2026
Oct 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vu...Show more
Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.Show less
1Samsung
1Android
Jun 17, 2026
Oct 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for...Show more
Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.Show less
1Samsung
1Android
Jun 17, 2026
Oct 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vu...Show more
Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.Show less
1Samsung
1Android
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execute privileged behaviors.
1Samsung
1Android
Jun 17, 2026
Sep 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.