VendorsSamsungandroidall versions
Vulnerabilities

Samsung Android 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

511CVEs
CVE-2025-21009
Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
Published 2025-07-08 · Analyzed
5.5EPSS 0.001
CVE-2025-21054
Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.
Published 2025-10-10 · Analyzed
5.5EPSS 0.001
CVE-2025-21005
Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.
Published 2025-07-08 · Analyzed
5.5EPSS 0.001
CVE-2025-21033
Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.
Published 2025-09-03 · Analyzed
5.5EPSS 0.001
CVE-2025-20985
Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items.
Published 2025-06-04 · Analyzed
5.5EPSS 0.001
CVE-2025-21028
Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
Published 2025-09-03 · Analyzed
5.5EPSS 0.001
CVE-2026-21016
Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-05-13 · Analyzed
5.5EPSS 0.001
CVE-2026-21112
Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.
Published 2026-09-09 · Analyzed
5.5EPSS 0.001
CVE-2026-21017
Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.
Published 2026-06-05 · Analyzed
5.5EPSS 0.001
CVE-2026-21028
Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-06-05 · Analyzed
5.5EPSS 0.001
CVE-2026-21099
Improper access control in SettingsProvider prior to SMR Sep-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-09-09 · Analyzed
5.5EPSS 0.001
CVE-2024-34590
Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
5.3EPSS 0.004
CVE-2024-34591
Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
5.3EPSS 0.004
CVE-2024-34592
Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
5.3EPSS 0.004
CVE-2023-21479
Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.
Published 2025-09-03 · Analyzed
5.3EPSS 0.004
CVE-2023-21485
Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
Published 2023-05-04 · Modified
5.3EPSS 0.003
CVE-2023-21486
Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
Published 2023-05-04 · Modified
5.3EPSS 0.003
CVE-2023-30700
PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.
Published 2023-08-10 · Modified
5.3EPSS 0.001
CVE-2024-20830
Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.
Published 2024-03-05 · Analyzed
5.3EPSS 0.001
CVE-2023-21466
PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.
Published 2025-09-03 · Analyzed
5.3EPSS 0.001
CVE-2023-42559
Improper exception management vulnerability in Knox Guard prior to SMR Dec-2023 Release 1 allows Knox Guard lock bypass via changing system time.
Published 2023-12-05 · Modified
5.2EPSS 0.003
CVE-2024-49422
Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.
Published 2024-12-31 · Analyzed
5.2EPSS 0.002
CVE-2026-20974
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
Published 2026-01-09 · Analyzed
5.2EPSS 0.002
CVE-2025-20989
Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key.
Published 2025-06-04 · Analyzed
5.2EPSS 0.001
CVE-2026-21070
Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.
Published 2026-08-10 · Analyzed
5.1EPSS 0.002
CVE-2023-30667
Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.
Published 2023-07-06 · Modified
5.1EPSS 0.002
CVE-2023-21424
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.
Published 2023-02-09 · Modified
5.1EPSS 0.002
CVE-2023-21487
Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.
Published 2023-05-04 · Modified
5.1EPSS 0.001
CVE-2025-20893
Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications.
Published 2025-02-04 · Analyzed
5.1EPSS 0.001
CVE-2024-34641
Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.
Published 2024-09-04 · Analyzed
5.1EPSS 0.001
CVE-2024-20811
Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.
Published 2024-02-06 · Modified
5.1EPSS 0.001
CVE-2025-20953
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.
Published 2025-05-07 · Analyzed
5.1EPSS 0.001
CVE-2024-20885
Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.
Published 2024-06-04 · Analyzed
5.1EPSS 0.001
CVE-2025-20991
Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.
Published 2025-06-04 · Analyzed
5.1EPSS 0.001
CVE-2025-21025
Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.
Published 2025-09-03 · Analyzed
5.1EPSS 0.001
CVE-2025-21027
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.
Published 2025-09-03 · Analyzed
5.1EPSS 0.001
CVE-2026-20989
Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.
Published 2026-03-16 · Analyzed
5.1EPSS 0.001
CVE-2026-20972
Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.
Published 2026-01-09 · Analyzed
4.8EPSS 0.001
CVE-2026-21062
Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.
Published 2026-08-10 · Analyzed
4.8EPSS 0.001
CVE-2026-20992
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
Published 2026-03-16 · Analyzed
4.8EPSS 0.001
← Prev11 / 13Next →