VendorsSamsungandroid14.0
Vulnerabilities

Samsung Android 9.0 14.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

302CVEs
CVE-2025-20999
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.
Published 2025-07-08 · Analyzed
4.1EPSS 0.002
CVE-2025-20962
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.
Published 2025-05-07 · Analyzed
4.0EPSS 0.001
CVE-2024-20860
Improper export of android application components vulnerability in TelephonyUI prior to SMR May-2024 Release 1 allows local attackers to reboot the device without proper permission.
Published 2024-05-07 · Analyzed
4.0EPSS 0.001
CVE-2024-34677
Exposure of sensitive information in System UI prior to SMR Nov-2024 Release 1 allow local attackers to make malicious apps appear as legitimate.
Published 2024-11-06 · Analyzed
4.0EPSS 0.001
CVE-2024-20847
Improper Access Control vulnerability in StorageManagerService prior to SMR Apr-2024 Release 1 allows local attackers to read sdcard information.
Published 2024-04-02 · Analyzed
4.0EPSS 0.001
CVE-2024-20900
Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.
Published 2024-07-02 · Modified
4.0EPSS 0.001
CVE-2024-34652
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.
Published 2024-09-04 · Analyzed
4.0EPSS 0.001
CVE-2024-34650
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.
Published 2024-09-04 · Analyzed
4.0EPSS 0.001
CVE-2024-34583
Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.
Published 2024-07-02 · Modified
4.0EPSS 0.001
CVE-2024-34618
Improper access control in System property prior to SMR Aug-2024 Release 1 allows local attackers to access cell related information.
Published 2024-08-07 · Analyzed
4.0EPSS 0.001
CVE-2024-34617
Improper handling of insufficient permission in Telephony prior to SMR Aug-2024 Release 1 allows local attackers to configure default Message application.
Published 2024-08-07 · Analyzed
4.0EPSS 0.001
CVE-2025-20960
Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.
Published 2025-05-07 · Analyzed
4.0EPSS 0.001
CVE-2025-20990
Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
Published 2025-08-06 · Analyzed
4.0EPSS 0.001
CVE-2025-21029
Improper handling of insufficient permission in System UI prior to SMR Sep-2025 Release 1 allows local attackers to send arbitrary replies to messages from the cover display.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
CVE-2025-21026
Improper handling of insufficient permission in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to interrupt the call.
Published 2025-09-03 · Analyzed
4.0EPSS 0.001
CVE-2024-20834
The sensitive information exposure vulnerability in WlanTest prior to SMR Mar-2024 Release 1 allows local attackers to access MAC address without proper permission.
Published 2024-03-05 · Analyzed
3.3EPSS 0.001
CVE-2024-34640
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
Published 2024-09-04 · Analyzed
3.3EPSS 0.001
CVE-2024-20855
Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.
Published 2024-05-07 · Analyzed
2.4EPSS 0.002
CVE-2024-49414
Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.
Published 2024-12-03 · Analyzed
2.4EPSS 0.002
CVE-2024-34649
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.
Published 2024-09-04 · Analyzed
2.4EPSS 0.002
CVE-2024-34682
Improper authorization in Settings prior to SMR Nov-2024 Release 1 allows physical attackers to access stored WiFi password in Maintenance Mode.
Published 2024-11-06 · Analyzed
2.4EPSS 0.002
CVE-2025-21046
Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent app list.
Published 2025-10-10 · Analyzed
2.4EPSS 0.002
← Prev8 / 8