VendorsSamsungandroidall versions
Vulnerabilities

Samsung Android 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

511CVEs
CVE-2023-21493
Improper access control vulnerability in SemShareFileProvider prior to SMR May-2023 Release 1 allows local attackers to access protected data.
Published 2023-05-04 · Modified
6.8EPSS 0.002
CVE-2026-21011
Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.
Published 2026-04-13 · Analyzed
6.8EPSS 0.001
CVE-2025-20993
Out-of-bounds write in libsecimaging.camera.samsung.so prior to SMR Jun-2025 Release 1 allows local attackers to write out-of-bounds memory.
Published 2025-06-04 · Analyzed
6.8EPSS 0.001
CVE-2025-21031
Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.
Published 2025-09-03 · Analyzed
6.8EPSS 0.001
CVE-2026-21012
External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.
Published 2026-04-13 · Analyzed
6.8EPSS 0.001
CVE-2026-21015
Incorrect default permissions in FactoryCamera prior to SMR May-2026 Release 1 allows local attacker to access unique identifier.
Published 2026-05-13 · Analyzed
6.8EPSS 0.001
CVE-2026-20988
Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability.
Published 2026-03-16 · Analyzed
6.8EPSS 0.001
CVE-2023-42557
Out-of-bound write vulnerability in libIfaaCa prior to SMR Dec-2023 Release 1 allows local system attackers to execute arbitrary code.
Published 2023-12-05 · Modified
6.7EPSS 0.003
CVE-2026-21060
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.
Published 2026-08-10 · Analyzed
6.7EPSS 0.002
CVE-2024-20862
Out-of-bounds write in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2024-05-07 · Analyzed
6.7EPSS 0.002
CVE-2024-20863
Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2024-05-07 · Analyzed
6.7EPSS 0.002
CVE-2024-20861
Use after free vulnerability in SveService prior to SMR May-2024 Release 1 allows local privileged attackers to cause memory corruption.
Published 2024-05-07 · Analyzed
6.7EPSS 0.002
CVE-2026-20968
Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2026-01-09 · Analyzed
6.7EPSS 0.002
CVE-2024-20843
Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2024-04-02 · Analyzed
6.7EPSS 0.002
CVE-2025-20937
Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-05-07 · Analyzed
6.7EPSS 0.002
CVE-2023-30654
Improper access control vulnerability in SLocationService prior to SMR Aug-2023 Release 1 allows local attacker to update fake location.
Published 2023-08-10 · Modified
6.7EPSS 0.002
CVE-2024-20832
Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2024-03-05 · Analyzed
6.7EPSS 0.002
CVE-2024-20842
Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2024-04-02 · Analyzed
6.7EPSS 0.002
CVE-2025-20904
Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.
Published 2025-02-04 · Analyzed
6.7EPSS 0.002
CVE-2025-20905
Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.
Published 2025-02-04 · Analyzed
6.7EPSS 0.002
CVE-2024-20831
Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2024-03-05 · Analyzed
6.7EPSS 0.002
CVE-2024-20881
Improper input validation vulnerability in chnactiv TA prior to SMR Jun-2024 Release 1 allows local privileged attackers lead to potential arbitrary code execution.
Published 2024-06-04 · Analyzed
6.7EPSS 0.002
CVE-2025-20987
Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a auth_token.
Published 2025-06-04 · Analyzed
6.7EPSS 0.001
CVE-2025-20885
Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memory corruption.
Published 2025-02-04 · Modified
6.7EPSS 0.001
CVE-2025-20982
Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-07-08 · Analyzed
6.7EPSS 0.001
CVE-2025-20983
Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2025-07-08 · Analyzed
6.7EPSS 0.001
CVE-2026-21097
Improper authentication in ActivityTaskManagerService prior to SMR Sep-2026 Release 1 allows local privileged attackers to launch arbitrary activity.
Published 2026-09-09 · Analyzed
6.7EPSS 0.001
CVE-2026-20991
Improper privilege management in ThemeManager prior to SMR Mar-2026 Release 1 allows local privileged attackers to reuse trial contents.
Published 2026-03-16 · Analyzed
6.7EPSS 0.001
CVE-2026-21093
Stack-based buffer overflow in PROCA trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.
Published 2026-09-09 · Analyzed
6.7EPSS 0.001
CVE-2024-20866
Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.
Published 2024-05-07 · Analyzed
6.6EPSS 0.003
CVE-2026-20981
Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege.
Published 2026-02-04 · Analyzed
6.6EPSS 0.002
CVE-2023-42564
Improper access control in knoxcustom service prior to SMR Dec-2023 Release 1 allows attacker to send broadcast with system privilege.
Published 2023-12-05 · Modified
6.6EPSS 0.002
CVE-2024-34646
Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.
Published 2024-09-04 · Analyzed
6.6EPSS 0.001
CVE-2026-21061
Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.
Published 2026-08-10 · Analyzed
6.5EPSS 0.004
CVE-2024-34588
Improper input validation혻in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
6.5EPSS 0.004
CVE-2024-34589
Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
6.5EPSS 0.004
CVE-2025-20908
Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.
Published 2025-03-06 · Analyzed
6.5EPSS 0.003
CVE-2025-58477
Out-of-bounds write in parsing IFD tag in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
6.5EPSS 0.003
CVE-2023-21427
Improper access control vulnerability in NfcTile prior to SMR Jan-2023 Release 1 allows to attacker to use NFC without user recognition.
Published 2023-02-09 · Modified
6.5EPSS 0.003
CVE-2026-21008
Exposure of sensitive information in S Share prior to SMR Apr-2026 Release 1 allows adjacent attacker to access sensitive information.
Published 2026-04-13 · Analyzed
6.5EPSS 0.002
← Prev7 / 13Next →