Vulnerabilities > Samsung > Android > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-05-07 CVE-2024-20866 Unspecified vulnerability in Samsung Android 12.0/13.0
Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.
low complexity
samsung
6.6
2024-04-02 CVE-2024-20842 Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0
Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
local
low complexity
samsung CWE-787
6.7
2024-04-02 CVE-2024-20843 Out-of-bounds Write vulnerability in Samsung Android 12.0/13.0
Out-of-bound write vulnerability in command parsing implementation of libIfaaCa prior to SMR Apr-2024 Release 1 allows local privileged attackers to execute arbitrary code.
local
low complexity
samsung CWE-787
6.7
2024-03-05 CVE-2024-20833 Use After Free vulnerability in Samsung Android 11.0/12.0
Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.
local
high complexity
samsung CWE-416
6.4
2024-03-05 CVE-2024-20830 Incorrect Default Permissions vulnerability in Samsung Android 11.0/12.0
Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.
local
low complexity
samsung CWE-276
5.3
2024-03-05 CVE-2024-20831 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0
Stack overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.
local
low complexity
samsung CWE-787
6.7
2024-03-05 CVE-2024-20832 Out-of-bounds Write vulnerability in Samsung Android 11.0/12.0
Heap overflow in Little Kernel in bootloader prior to SMR Mar-2024 Release 1 allows local privileged attackers to execute arbitrary code.
local
low complexity
samsung CWE-787
6.7
2024-03-05 CVE-2024-20836 Out-of-bounds Read vulnerability in Samsung Android 11.0/12.0
Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.
local
low complexity
samsung CWE-125
5.5
2024-02-06 CVE-2024-20814 Out-of-bounds Read vulnerability in Samsung Android 11.0/12.0
Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.
local
low complexity
samsung CWE-125
5.5
2024-02-06 CVE-2024-20815 Improper Authentication vulnerability in Samsung Android 11.0/12.0
Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connect to victim's mobile hotspot without user awareness.
low complexity
samsung CWE-287
6.5