CVE-2025-20909
- EPSS 0.06%
- Veröffentlicht 06.03.2025 05:15:17
- Zuletzt bearbeitet 24.02.2026 17:59:09
Use of implicit intent for sensitive communication in Settings prior to SMR Mar-2025 Release 1 allows local attackers to access sensitive information.
CVE-2025-20903
- EPSS 0.05%
- Veröffentlicht 06.03.2025 05:15:16
- Zuletzt bearbeitet 05.02.2026 19:00:31
Improper access control in SecSettingsIntelligence prior to SMR Mar-2025 Release 1 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
CVE-2025-20904
- EPSS 0.11%
- Veröffentlicht 04.02.2025 08:15:32
- Zuletzt bearbeitet 12.02.2025 13:48:47
Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.
CVE-2025-20905
- EPSS 0.1%
- Veröffentlicht 04.02.2025 08:15:32
- Zuletzt bearbeitet 12.02.2025 13:49:26
Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.
CVE-2025-20907
- EPSS 0.06%
- Veröffentlicht 04.02.2025 08:15:32
- Zuletzt bearbeitet 12.02.2025 13:49:49
Improper privilege management in Samsung Find prior to SMR Feb-2025 Release 1 allows local privileged attackers to disable Samsung Find.
CVE-2025-20890
- EPSS 0.11%
- Veröffentlicht 04.02.2025 08:15:30
- Zuletzt bearbeitet 12.02.2025 13:47:05
Out-of-bounds write in decoding frame buffer in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.
CVE-2025-20891
- EPSS 0.13%
- Veröffentlicht 04.02.2025 08:15:30
- Zuletzt bearbeitet 12.02.2025 13:47:21
Out-of-bounds read in decoding malformed bitstream of video thumbnails in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.
CVE-2025-20892
- EPSS 0.17%
- Veröffentlicht 04.02.2025 08:15:30
- Zuletzt bearbeitet 12.02.2025 13:47:40
Protection Mechanism Failure in bootloader prior to SMR Jan-2025 Release 1 allows physical attackers to allow to execute fastboot command. User interaction is required for triggering this vulnerability.
CVE-2025-20893
- EPSS 0.1%
- Veröffentlicht 04.02.2025 08:15:30
- Zuletzt bearbeitet 12.02.2025 13:48:39
Improper access control in NotificationManager prior to SMR Jan-2025 Release 1 allows local attackers to change the configuration of notifications.
CVE-2025-20882
- EPSS 0.06%
- Veröffentlicht 04.02.2025 08:15:29
- Zuletzt bearbeitet 12.02.2025 13:43:13
Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.