VendorsSamsungandroid15.0
Vulnerabilities

Samsung Android 9.0 15.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

147CVEs
CVE-2026-20968
Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2026-01-09 · Analyzed
6.7EPSS 0.002
CVE-2025-20937
Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-05-07 · Analyzed
6.7EPSS 0.002
CVE-2025-20987
Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a auth_token.
Published 2025-06-04 · Analyzed
6.7EPSS 0.001
CVE-2025-20982
Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-07-08 · Analyzed
6.7EPSS 0.001
CVE-2025-20983
Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-07-08 · Analyzed
6.7EPSS 0.001
CVE-2026-21097
Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.
Published 2026-09-09 · Analyzed
6.7EPSS 0.001
CVE-2026-20991
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
Published 2026-03-16 · Analyzed
6.7EPSS 0.001
CVE-2026-21093
Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2026-09-09 · Analyzed
6.7EPSS 0.001
CVE-2026-20981
Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.
Published 2026-02-04 · Analyzed
6.6EPSS 0.002
CVE-2026-21061
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.
Published 2026-08-10 · Analyzed
6.5EPSS 0.004
CVE-2025-20908
Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.
Published 2025-03-06 · Analyzed
6.5EPSS 0.003
CVE-2025-58477
Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
6.5EPSS 0.003
CVE-2026-21008
Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.
Published 2026-04-13 · Analyzed
6.5EPSS 0.002
CVE-2025-20943
Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.
Published 2025-04-08 · Analyzed
6.4EPSS 0.001
CVE-2025-20941
Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.
Published 2025-04-08 · Analyzed
6.2EPSS 0.001
CVE-2025-20981
Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information.
Published 2025-06-04 · Analyzed
6.2EPSS 0.001
CVE-2025-21000
Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.
Published 2025-07-08 · Analyzed
6.2EPSS 0.001
CVE-2025-21001
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.
Published 2025-07-08 · Analyzed
6.2EPSS 0.001
CVE-2025-21002
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.
Published 2025-07-08 · Analyzed
6.2EPSS 0.001
CVE-2026-21073
Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.
Published 2026-08-10 · Analyzed
6.1EPSS 0.002
CVE-2026-20978
Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
Published 2026-02-04 · Analyzed
6.1EPSS 0.001
CVE-2025-21010
Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.
Published 2025-08-06 · Analyzed
6.0EPSS 0.001
CVE-2026-21105
Improper access control in Collection prior to version 1.0.1.14 in Android 15 and 2.0.02.7 in Android 16 allows local attackers to access sensitive information.
Published 2026-09-09 · Analyzed
5.9EPSS 0.001
CVE-2025-21044
Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-10-10 · Analyzed
5.7EPSS 0.001
CVE-2025-21071
Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-11-05 · Analyzed
5.7EPSS 0.001
CVE-2025-21072
Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-12-02 · Analyzed
5.7EPSS 0.001
CVE-2025-58475
Improper input validation in libsec-ril.so prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-12-02 · Analyzed
5.6EPSS 0.001
CVE-2026-20969
Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability.
Published 2026-01-09 · Analyzed
5.5EPSS 0.003
CVE-2025-20947
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.
Published 2025-04-08 · Analyzed
5.5EPSS 0.002
CVE-2025-20954
Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
Published 2025-05-07 · Analyzed
5.5EPSS 0.002
CVE-2025-20955
Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.
Published 2025-05-07 · Analyzed
5.5EPSS 0.001
CVE-2025-20952
Improper access control in Mdecservice prior to SMR Apr-2025 Release 1 allows local attackers to access arbitrary files with system privilege.
Published 2025-04-09 · Analyzed
5.5EPSS 0.001
CVE-2025-20961
Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.
Published 2025-05-07 · Analyzed
5.5EPSS 0.001
CVE-2025-21049
Improper access control in SecSettings prior to SMR Oct-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
Published 2025-10-10 · Analyzed
5.5EPSS 0.001
CVE-2025-20959
Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.
Published 2025-05-07 · Analyzed
5.5EPSS 0.001
CVE-2025-21014
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
Published 2025-08-06 · Analyzed
5.5EPSS 0.001
CVE-2025-21003
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.
Published 2025-07-08 · Analyzed
5.5EPSS 0.001
CVE-2025-21054
Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.
Published 2025-10-10 · Analyzed
5.5EPSS 0.001
CVE-2025-21033
Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.
Published 2025-09-03 · Analyzed
5.5EPSS 0.001
CVE-2025-20985
Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items.
Published 2025-06-04 · Analyzed
5.5EPSS 0.001
← Prev3 / 4Next →