VendorsSamsungandroid14.0
Vulnerabilities

Samsung Android 9.0 14.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

302CVEs
CVE-2024-20892
Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
7.8EPSS 0.001
CVE-2026-21089
Improper input validation in removing style tag in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Published 2026-09-09 · Analyzed
7.8EPSS 0.001
CVE-2026-21010
Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.
Published 2026-04-13 · Analyzed
7.8EPSS 0.001
CVE-2026-21091
Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Published 2026-09-09 · Analyzed
7.8EPSS 0.001
CVE-2026-21090
Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.
Published 2026-09-09 · Analyzed
7.8EPSS 0.001
CVE-2026-21020
Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions.
Published 2026-05-13 · Analyzed
7.8EPSS 0.001
CVE-2026-21030
Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.
Published 2026-06-05 · Analyzed
7.8EPSS 0.001
CVE-2026-21029
Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.
Published 2026-06-05 · Analyzed
7.8EPSS 0.001
CVE-2025-20992
Out-of-bound read in libsecimaging.camera.samsung.so prior to SMR Feb-2025 Release 1 allows local attackers to read out-of-bounds memory.
Published 2025-06-04 · Analyzed
7.7EPSS 0.002
CVE-2024-20895
Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.
Published 2024-07-02 · Modified
7.7EPSS 0.001
CVE-2024-34587
Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
7.5EPSS 0.005
CVE-2025-21055
Out-of-bounds read and write in libimagecodec.quram.so prior to SMR Oct-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Published 2025-10-10 · Analyzed
7.5EPSS 0.003
CVE-2025-21074
Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Published 2025-11-05 · Analyzed
7.5EPSS 0.003
CVE-2025-58479
Out-of-bounds read in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
7.5EPSS 0.003
CVE-2025-58480
Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
7.5EPSS 0.003
CVE-2025-21075
Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Published 2025-11-05 · Analyzed
7.5EPSS 0.003
CVE-2025-58478
Out-of-bounds write in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
7.5EPSS 0.003
CVE-2023-42565
Improper input validation vulnerability in Smart Clip prior to SMR Dec-2023 Release 1 allows local attackers with shell privilege to execute arbitrary code.
Published 2023-12-05 · Modified
7.3EPSS 0.002
CVE-2024-34676
Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required for triggering this vulnerability.
Published 2024-11-06 · Analyzed
7.3EPSS 0.002
CVE-2025-20903
Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
Published 2025-03-06 · Analyzed
7.3EPSS 0.002
CVE-2023-42561
Heap out-of-bounds write vulnerability in bootloader prior to SMR Dec-2023 Release 1 allows a physical attacker to execute arbitrary code.
Published 2023-12-05 · Modified
7.1EPSS 0.004
CVE-2025-20944
Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.
Published 2025-04-08 · Analyzed
7.1EPSS 0.002
CVE-2025-20948
Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
Published 2025-04-08 · Analyzed
7.1EPSS 0.002
CVE-2023-52432
Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.
Published 2024-03-05 · Analyzed
7.1EPSS 0.002
CVE-2025-20988
Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
Published 2025-06-04 · Analyzed
7.1EPSS 0.002
CVE-2024-49401
Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities.
Published 2024-11-06 · Analyzed
7.1EPSS 0.002
CVE-2024-20879
Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.
Published 2024-06-04 · Analyzed
7.1EPSS 0.001
CVE-2026-21058
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Published 2026-08-10 · Analyzed
7.1EPSS 0.001
CVE-2024-34638
Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.
Published 2024-09-04 · Analyzed
7.1EPSS 0.001
CVE-2024-34679
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.
Published 2024-11-06 · Analyzed
7.1EPSS 0.001
CVE-2025-21050
Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.
Published 2025-10-10 · Analyzed
7.1EPSS 0.001
CVE-2026-21100
Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.
Published 2026-09-09 · Analyzed
7.1EPSS 0.001
CVE-2026-20980
Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.
Published 2026-02-04 · Analyzed
7.0EPSS 0.002
CVE-2026-21064
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
Published 2026-08-10 · Analyzed
7.0EPSS 0.001
CVE-2026-20977
Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.
Published 2026-02-04 · Analyzed
6.9EPSS 0.001
CVE-2026-21023
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
Published 2026-04-29 · Analyzed
6.9EPSS 0.001
CVE-2026-21025
Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-06-05 · Analyzed
6.9EPSS 0.001
CVE-2024-20865
Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.
Published 2024-05-07 · Analyzed
6.8EPSS 0.003
CVE-2026-20982
Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.
Published 2026-02-04 · Analyzed
6.8EPSS 0.003
CVE-2023-42577
Improper Access Control in Samsung Voice Recorder prior to versions 21.4.15.01 in Android 12 and Android 13, 21.4.50.17 in Android 14 allows physical attackers to access Voice Recorder information on the lock screen.
Published 2023-12-05 · Modified
6.8EPSS 0.003
← Prev3 / 8Next →