Skip to main content

Vendor/product archive

samsung / android CVEs

Beta · best-effort

475 CVEs tagged to samsung / android1 Critical, 86 High, 367 Medium, 21 Low, 0 Unrated.

CVE-2024-34676

Published Nov 6, 2024

Out-of-bounds write in parsing subtitle file in libsubextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. User interaction is required…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34675

Published Nov 6, 2024

Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to unlocked screen.

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-34674

Published Nov 6, 2024

Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34673

Published Nov 6, 2024

Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34672

Published Oct 8, 2024

Improper input validation in SamsungVideoPlayer prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android 14 allows local attackers to access vid…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34669

Published Oct 8, 2024

Out-of-bounds write in parsing h.263+ format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User inte…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34668

Published Oct 8, 2024

Out-of-bounds write in parsing h.263 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User inter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34667

Published Oct 8, 2024

Out-of-bounds write in parsing h.265 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User inter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34666

Published Oct 8, 2024

Out-of-bounds write in parsing h.264 format in a specific mode in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system pr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34665

Published Oct 8, 2024

Out-of-bounds write in parsing h.264 format in librtppayload.so prior to SMR Oct-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User inter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34662

Published Oct 8, 2024

Improper access control in ActivityManager prior to SMR Oct-2024 Release 1 in select Android 12, 13 and SMR Sep-2024 Release 1 in select Android 14 allows local attackers to execu…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34655

Published Sep 4, 2024

Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34654

Published Sep 4, 2024

Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34653

Published Sep 4, 2024

Path Traversal in My Files prior to SMR Sep-2024 Release 1 allows physical attackers to access directories with My Files' privilege.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34652

Published Sep 4, 2024

Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34651

Published Sep 4, 2024

Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34650

Published Sep 4, 2024

Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to Edge panel.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34649

Published Sep 4, 2024

Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-34648

Published Sep 4, 2024

Improper Handling of Insufficient Permissions in KnoxMiscPolicy prior to SMR Sep-2024 Release 1 allows local attackers to access sensitive data.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34647

Published Sep 4, 2024

Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34646

Published Sep 4, 2024

Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34645

Published Sep 4, 2024

Improper input validation in ThemeCenter prior to SMR Sep-2024 Release 1 allows physical attackers to install privileged applications.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34644

Published Sep 4, 2024

Improper access control in item selection related in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required for tr…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34643

Published Sep 4, 2024

Improper access control in key input related function in Dressroom prior to SMR Sep-2024 Release 1 allows local attackers to access protected data. User interaction is required fo…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34642

Published Sep 4, 2024

Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access sensitive information.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 475 CVEsPage 8 of 19