Vulnerabilities > Samsung > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-02-04 CVE-2025-20905 Out-of-bounds Read vulnerability in Samsung Android 12.0/13.0/14.0
Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.
local
low complexity
samsung CWE-125
6.7
2025-02-04 CVE-2025-20907 Unspecified vulnerability in Samsung Android 12.0/13.0
Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.
local
low complexity
samsung
4.4
2024-12-03 CVE-2024-49411 Path Traversal vulnerability in Samsung Android 12.0/13.0
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
low complexity
samsung CWE-22
4.6
2024-11-06 CVE-2024-34673 Unspecified vulnerability in Samsung Android 12.0/13.0/14.0
Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.
local
low complexity
samsung
5.5
2024-11-06 CVE-2024-34674 Unspecified vulnerability in Samsung Android 12.0/13.0/14.0
Improper access control in Contacts prior to SMR Nov-2024 Release 1 allows physical attackers to access data across multiple user profiles.
low complexity
samsung
4.6
2024-11-06 CVE-2024-34675 Unspecified vulnerability in Samsung Android 14.0
Improper access control in Dex Mode prior to SMR Nov-2024 Release 1 allows physical attackers to temporarily access to unlocked screen.
low complexity
samsung
4.6
2024-11-06 CVE-2024-34680 Unspecified vulnerability in Samsung Android 12.0/13.0/14.0
Use of implicit intent for sensitive communication in WlanTest prior to SMR Nov-2024 Release 1 allows local attackers to get sensitive information.
local
low complexity
samsung
5.5
2024-11-06 CVE-2024-49402 Unspecified vulnerability in Samsung Android 14.0
Improper input validation in Dressroom prior to SMR Nov-2024 Release 1 allow physical attackers to access data across multiple user profiles.
low complexity
samsung
4.6
2024-09-04 CVE-2024-34637 Unspecified vulnerability in Samsung Android 12.0/13.0/14.0
Improper access control in WindowManagerService prior to SMR Sep-2024 Release 1 in Android 12, and SMR Jun-2024 Release 1 in Android 13 and Android 14 allows local attackers to bypass restrictions on starting services from the background.
local
low complexity
samsung
5.5
2024-09-04 CVE-2024-34639 Improper Handling of Exceptional Conditions vulnerability in Samsung Android 12.0/13.0/14.0
Improper handling of exceptional conditions in Setupwizard prior to SMR Aug-2024 Release 1 allows physical attackers to bypass proper validation.
low complexity
samsung CWE-755
4.6