VendorsSamsungandroid13.0
Vulnerabilities

Samsung Android 9.0 13.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

367CVEs
CVE-2024-34616
Improper handling of insufficient permission in KnoxDualDARPolicy prior to SMR Aug-2024 Release 1 allows local attackers to access sensitive data.
Published 2024-08-07 · Analyzed
5.5EPSS 0.001
CVE-2025-21014
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
Published 2025-08-06 · Analyzed
5.5EPSS 0.001
CVE-2025-21003
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.
Published 2025-07-08 · Analyzed
5.5EPSS 0.001
CVE-2024-34611
Improper access control in KnoxService prior to SMR Aug-2024 Release 1 allows local attackers to get sensitive information.
Published 2024-08-07 · Analyzed
5.5EPSS 0.001
CVE-2025-21054
Out-of-bounds read in the parsing header for JPEG decoding in libpadm.so prior to SMR Oct-2025 Release 1 allows local attackers to potentially access out-of-bounds memory.
Published 2025-10-10 · Analyzed
5.5EPSS 0.001
CVE-2025-20985
Improper privilege management in ThemeManager prior to SMR Jun-2025 Release 1 allows local privileged attackers to reuse trial items.
Published 2025-06-04 · Analyzed
5.5EPSS 0.001
CVE-2024-34590
Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
5.3EPSS 0.004
CVE-2024-34591
Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
5.3EPSS 0.004
CVE-2024-34592
Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction is required for triggering this vulnerability.
Published 2024-07-02 · Modified
5.3EPSS 0.004
CVE-2023-21479
Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.
Published 2025-09-03 · Analyzed
5.3EPSS 0.004
CVE-2023-21486
Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
Published 2023-05-04 · Modified
5.3EPSS 0.003
CVE-2023-21485
Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
Published 2023-05-04 · Modified
5.3EPSS 0.003
CVE-2023-30700
PendingIntent hijacking vulnerability in SemWifiApTimeOutImpl in framework prior to SMR Aug-2023 Release 1 allows local attackers to access ContentProvider without proper permission.
Published 2023-08-10 · Modified
5.3EPSS 0.001
CVE-2024-20830
Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.
Published 2024-03-05 · Analyzed
5.3EPSS 0.001
CVE-2023-21466
PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.
Published 2025-09-03 · Analyzed
5.3EPSS 0.001
CVE-2024-49422
Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.
Published 2024-12-31 · Analyzed
5.2EPSS 0.002
CVE-2026-20974
Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock.
Published 2026-01-09 · Analyzed
5.2EPSS 0.002
CVE-2025-20989
Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key.
Published 2025-06-04 · Analyzed
5.2EPSS 0.001
CVE-2023-30667
Improper access control in Audio system service prior to SMR Jul-2023 Release 1 allows attacker to send broadcast with system privilege.
Published 2023-07-06 · Modified
5.1EPSS 0.002
CVE-2023-21424
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper prior to SMR Jan-2023 Release 1 allows attacker to modify network related values, network code, carrier id and operator brand.
Published 2023-02-09 · Modified
5.1EPSS 0.002
CVE-2023-21487
Improper access control vulnerability in Telephony framework prior to SMR May-2023 Release 1 allows local attackers to change a call setting.
Published 2023-05-04 · Modified
5.1EPSS 0.001
CVE-2025-20953
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.
Published 2025-05-07 · Analyzed
5.1EPSS 0.001
CVE-2024-20811
Improper caller verification in GameOptimizer prior to SMR Feb-2024 Release 1 allows local attackers to configure GameOptimizer.
Published 2024-02-06 · Modified
5.1EPSS 0.001
CVE-2024-34641
Improper Export of Android Application Components in FeliCaTest prior to SMR Sep-2024 Release 1 allows local attackers to enable NFC configuration.
Published 2024-09-04 · Analyzed
5.1EPSS 0.001
CVE-2025-20991
Improper export of Android application components in Bluetooth prior to SMR Jun-2025 Release 1 allows local attackers to make devices discoverable.
Published 2025-06-04 · Analyzed
5.1EPSS 0.001
CVE-2025-21025
Improper access control in MARsExemptionManager prior to SMR Sep-2025 Release 1 allows local attackers to be excluded from background execution management.
Published 2025-09-03 · Analyzed
5.1EPSS 0.001
CVE-2025-21027
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.
Published 2025-09-03 · Analyzed
5.1EPSS 0.001
CVE-2026-20972
Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.
Published 2026-01-09 · Analyzed
4.8EPSS 0.001
CVE-2026-20992
Improper authorization in Settings prior to SMR Mar-2026 Release 1 allows local attacker to disable configuring the background data usage of application.
Published 2026-03-16 · Analyzed
4.8EPSS 0.001
CVE-2024-34653
Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.
Published 2024-09-04 · Analyzed
4.6EPSS 0.003
CVE-2024-49411
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
Published 2024-12-03 · Analyzed
4.6EPSS 0.002
CVE-2023-30714
Improper authorization vulnerability in FolderContainerDragDelegate in One UI Home prior to SMR Sep-2023 Release 1 allows physical attackers to change some settings of the folder lock.
Published 2023-09-06 · Modified
4.6EPSS 0.002
CVE-2024-34639
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
Published 2024-09-04 · Analyzed
4.6EPSS 0.002
CVE-2024-34642
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.
Published 2024-09-04 · Analyzed
4.6EPSS 0.002
CVE-2025-20883
Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
Published 2025-02-04 · Analyzed
4.6EPSS 0.002
CVE-2024-20882
Out-of-bounds read vulnerability in bootloader prior to SMR June-2024 Release 1 allows physical attackers to arbitrary data access.
Published 2024-06-04 · Analyzed
4.6EPSS 0.002
CVE-2024-34674
Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.
Published 2024-11-06 · Analyzed
4.6EPSS 0.002
CVE-2025-20884
Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
Published 2025-02-04 · Analyzed
4.6EPSS 0.002
CVE-2025-20966
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.
Published 2025-05-07 · Analyzed
4.6EPSS 0.002
CVE-2025-58476
Out-of-bounds read vulnerability in bootloader prior to SMR Dec-2025 Release 1 allows physical attackers to access out-of-bounds memory.
Published 2025-12-02 · Analyzed
4.6EPSS 0.001
← Prev8 / 10Next →