VendorsSamsungandroidall versions
Vulnerabilities

Samsung Android 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

511CVEs
CVE-2026-21027
Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.
Published 2026-06-05 · Analyzed
4.8EPSS 0.001
CVE-2026-21006
Improper access control in Samsung DeX prior to SMR Apr-2026 Release 1 allows physical attackers to access to hidden notification contents.
Published 2026-04-13 · Analyzed
4.7EPSS 0.001
CVE-2024-34653
Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.
Published 2024-09-04 · Analyzed
4.6EPSS 0.003
CVE-2024-49411
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
Published 2024-12-03 · Analyzed
4.6EPSS 0.002
CVE-2023-30714
Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.
Published 2023-09-06 · Modified
4.6EPSS 0.002
CVE-2024-34639
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
Published 2024-09-04 · Analyzed
4.6EPSS 0.002
CVE-2024-34642
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
Published 2024-09-04 · Analyzed
4.6EPSS 0.002
CVE-2025-20883
Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
Published 2025-02-04 · Analyzed
4.6EPSS 0.002
CVE-2024-49402
Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.
Published 2024-11-06 · Analyzed
4.6EPSS 0.002
CVE-2024-20882
Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.
Published 2024-06-04 · Analyzed
4.6EPSS 0.002
CVE-2024-34674
Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.
Published 2024-11-06 · Analyzed
4.6EPSS 0.002
CVE-2025-20884
Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
Published 2025-02-04 · Analyzed
4.6EPSS 0.002
CVE-2025-20966
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.
Published 2025-05-07 · Analyzed
4.6EPSS 0.002
CVE-2024-34675
Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to unlocked screen.
Published 2024-11-06 · Analyzed
4.6EPSS 0.002
CVE-2025-21063
Improper access control in Samsung Voice Recorder prior to version 21.5.73.12 in Android 15 and 21.5.81.40 in Android 16 allows physical attackers to access recording files on the lock screen.
Published 2025-10-10 · Analyzed
4.6EPSS 0.002
CVE-2025-58476
Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
4.6EPSS 0.001
CVE-2023-21492
Kernel pointers are printed in the log file prior to SMR May-2023 Release 1 allows a privileged local attacker to bypass ASLR.
Published 2023-05-04 · Analyzed
4.4KEVEPSS 0.026
CVE-2023-42552
Implicit intent hijacking vulnerability in Firewall application prior to versions 12.1.00.24 in Android 11, 13.1.00.16 in Android 12 and 14.1.00.7 in Android 13 allows 3rd party application to tamper the database of Firewall.
Published 2023-11-07 · Modified
4.4EPSS 0.002
CVE-2023-30721
Insertion of sensitive information into log vulnerability in Locksettings prior to SMR Sep-2023 Release 1 allows a privileged local attacker to get lock screen match information from the log.
Published 2023-09-06 · Modified
4.4EPSS 0.002
CVE-2023-30665
Improper input validation vulnerability in OnOemServiceMode in libsec-ril prior to SMR Jul-2023 Release 1 allows local attackers to cause an Out-Of-Bounds read.
Published 2023-07-06 · Modified
4.4EPSS 0.002
CVE-2023-21460
Improper authentication in SecSettings prior to SMR Mar-2023 Release 1 allows attacker to reset the setting.
Published 2023-03-16 · Modified
4.4EPSS 0.002
CVE-2025-20942
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.
Published 2025-04-08 · Analyzed
4.4EPSS 0.001
CVE-2025-20886
Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.
Published 2025-02-04 · Modified
4.4EPSS 0.001
CVE-2025-20958
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.
Published 2025-05-07 · Analyzed
4.4EPSS 0.001
CVE-2024-20856
Improper Authentication vulnerability in Secure Folder prior to SMR May-2024 Release 1 allows physical attackers to access Secure Folder without proper authentication in a specific scenario.
Published 2024-05-07 · Analyzed
4.3EPSS 0.003
CVE-2023-30641
Improper access control vulnerability in Settings prior to SMR Jul-2023 Release 1 allows physical attacker to use restricted user profile to access device owner's google account data.
Published 2023-07-06 · Modified
4.3EPSS 0.003
CVE-2024-20894
Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
4.3EPSS 0.002
CVE-2023-30685
Improper access control vulnerability in Telecom prior to SMR Aug-2023 Release 1 allows local attakcers to change TTY mode.
Published 2023-08-10 · Modified
4.3EPSS 0.002
CVE-2023-30682
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call silenceRinger API without permission.
Published 2023-08-10 · Modified
4.3EPSS 0.001
CVE-2023-30683
Improper access control in Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call endCall API without permission.
Published 2023-08-10 · Modified
4.3EPSS 0.001
CVE-2023-30684
Improper access control in Samsung Telecom prior to SMR Aug-2023 Release 1 allows local attackers to call acceptRingingCall API without permission.
Published 2023-08-10 · Modified
4.3EPSS 0.001
CVE-2023-30640
Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.
Published 2023-07-06 · Modified
4.3EPSS 0.001
CVE-2025-20999
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.
Published 2025-07-08 · Analyzed
4.1EPSS 0.002
CVE-2023-42569
Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.
Published 2023-12-05 · Modified
4.0EPSS 0.002
CVE-2023-21428
Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows attackers to configure Preferred Call. The patch removes unused code.
Published 2023-02-09 · Modified
4.0EPSS 0.002
CVE-2023-30719
Exposure of Sensitive Information vulnerability in InboundSmsHandler prior to SMR Sep-2023 Release 1 allows local attackers to access certain message data.
Published 2023-09-06 · Modified
4.0EPSS 0.002
CVE-2023-30711
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
Published 2023-09-06 · Modified
4.0EPSS 0.002
CVE-2023-30715
Improper access control vulnerability in Weather prior to SMR Sep-2023 Release 1 allows attackers to access location information set in Weather without permission.
Published 2023-09-06 · Modified
4.0EPSS 0.002
CVE-2023-30717
Sensitive information exposure vulnerability in SVCAgent prior to SMR Sep-2023 Release 1 allows attackers to get unresettable identifiers.
Published 2023-09-06 · Modified
4.0EPSS 0.002
CVE-2023-21429
Improper usage of implict intent in ePDG prior to SMR JAN-2023 Release 1 allows attacker to access SSID.
Published 2023-02-09 · Modified
4.0EPSS 0.002
← Prev12 / 13Next →