Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Filtered by product Android
Total 475 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-20944 1 Samsung 1 Android 2026-06-17 N/A 6.2 MEDIUM
Out-of-bounds read in parsing audio data in libsavsac.so prior to SMR Apr-2025 Release 1 allows local attackers to read out-of-bounds memory.
CVE-2025-20943 1 Samsung 1 Android 2026-06-17 N/A 6.4 MEDIUM
Out-of-bounds write in secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to cause memory corruption.
CVE-2025-20942 1 Samsung 1 Android 2026-06-17 N/A 4.4 MEDIUM
Improper Verification of Intent by Broadcast Receiver in DeviceIdService prior to SMR Apr-2025 Release 1 allows local attackers to reset OAID.
CVE-2025-20941 1 Samsung 1 Android 2026-06-17 N/A 6.2 MEDIUM
Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.
CVE-2025-20938 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Improper access control in SamsungContacts prior to SMR Apr-2025 Release 1 allows local attackers to access protected data in SamsungContacts.
CVE-2025-20937 1 Samsung 1 Android 2026-06-17 N/A 6.7 MEDIUM
Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
CVE-2025-20936 1 Samsung 1 Android 2026-06-17 N/A 8.8 HIGH
Improper access control in HDCP trustlet prior to SMR Apr-2025 Release 1 allows local attackers with shell privilege to escalate their privileges to root.
CVE-2025-20934 1 Samsung 1 Android 2026-06-17 N/A 5.5 MEDIUM
Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.
CVE-2025-20909 1 Samsung 1 Android 2026-06-17 N/A 4.0 MEDIUM
Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.
CVE-2025-20908 1 Samsung 1 Android 2026-06-17 N/A 6.5 MEDIUM
Use of insufficiently random values in Auracast prior to SMR Mar-2025 Release 1 allows adjacent attackers to access Auracast broadcasting.
CVE-2025-20907 1 Samsung 1 Android 2026-06-17 N/A 6.0 MEDIUM
Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.
CVE-2025-20905 1 Samsung 1 Android 2026-06-17 N/A 6.3 MEDIUM
Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.
CVE-2025-20904 1 Samsung 1 Android 2026-06-17 N/A 6.3 MEDIUM
Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.
CVE-2025-20903 1 Samsung 1 Android 2026-06-17 N/A 7.3 HIGH
Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
CVE-2025-20893 1 Samsung 1 Android 2026-06-17 N/A 5.1 MEDIUM
Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications.
CVE-2025-20892 1 Samsung 1 Android 2026-06-17 N/A 5.9 MEDIUM
Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. User interaction is required for triggering this vulnerability.
CVE-2025-20891 1 Samsung 1 Android 2026-06-17 N/A 5.3 MEDIUM
Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.
CVE-2025-20890 1 Samsung 1 Android 2026-06-17 N/A 7.0 HIGH
Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.
CVE-2025-20889 1 Samsung 1 Android 2026-06-17 N/A 5.3 MEDIUM
Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.
CVE-2025-20888 1 Samsung 1 Android 2026-06-17 N/A 7.0 HIGH
Out-of-bounds write in handling the block size for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.