Skip to main content

Vendor/product archive

samsung / android CVEs

Beta · best-effort

475 CVEs tagged to samsung / android1 Critical, 86 High, 367 Medium, 21 Low, 0 Unrated.

CVE-2024-34593

Published Jul 2, 2024

Improper input validation in parsing and distributing RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with system privil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34592

Published Jul 2, 2024

Improper input validation in parsing RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34591

Published Jul 2, 2024

Improper input validation in parsing an item data from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34590

Published Jul 2, 2024

Improper input validation혻in parsing an item type from RTCP SDES packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34589

Published Jul 2, 2024

Improper input validation in parsing RTCP RR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34588

Published Jul 2, 2024

Improper input validation혻in parsing RTCP SR packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to trigger temporary denial of service. User interaction i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34587

Published Jul 2, 2024

Improper input validation in parsing application information from RTCP packet in librtp.so prior to SMR Jul-2024 Release 1 allows remote attackers to execute arbitrary code with s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34586

Published Jul 2, 2024

Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34585

Published Jul 2, 2024

Improper access control in launchApp of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34583

Published Jul 2, 2024

Improper access control in system property prior to SMR Jul-2024 Release 1 allows local attackers to get device identifier.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20901

Published Jul 2, 2024

Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20900

Published Jul 2, 2024

Improper authentication in MTP application prior to SMR Jul-2024 Release 1 allows local attackers to enter MTP mode without proper authentication.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20899

Published Jul 2, 2024

Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20898

Published Jul 2, 2024

Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20897

Published Jul 2, 2024

Use of implicit intent for sensitive communication in FCM function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20896

Published Jul 2, 2024

Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20895

Published Jul 2, 2024

Improper access control in Dar service prior to SMR Jul-2024 Release 1 allows local attackers to bypass restriction for calling SDP features.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-20894

Published Jul 2, 2024

Improper handling of exceptional conditions in Secure Folder prior to SMR Jul-2024 Release 1 allows physical attackers to bypass authentication under certain condition. User inter…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20893

Published Jul 2, 2024

Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20892

Published Jul 2, 2024

Improper verification of signature in FilterProvider prior to SMR Jul-2024 Release 1 allows local attackers to execute privileged behaviors. User interaction is required for trigg…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20891

Published Jul 2, 2024

Improper access control in launchFullscreenIntent of SystemUI prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-20890

Published Jul 2, 2024

Improper input validation in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to trigger abnormal behavior.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20889

Published Jul 2, 2024

Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-20888

Published Jul 2, 2024

Improper access control in OneUIHome prior to SMR Jul-2024 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulne…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-20885

Published Jun 4, 2024

Improper component protection vulnerability in Samsung Dialer prior to SMR May-2024 Release 1 allows local attackers to make a call without proper permission.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 475 CVEsPage 10 of 19