CVE-2025-21043
- EPSS 11.62%
- Published 12.09.2025 07:21:51
- Last modified 03.10.2025 01:00:02
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
CVE-2025-21033
- EPSS 0.02%
- Published 03.09.2025 06:05:38
- Last modified 11.09.2025 21:23:42
Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.
CVE-2025-21032
- EPSS 0.02%
- Published 03.09.2025 06:05:37
- Last modified 11.09.2025 21:23:27
Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.
CVE-2025-21031
- EPSS 0.02%
- Published 03.09.2025 06:05:36
- Last modified 05.09.2025 16:40:29
Improper access control in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to use the privileged APIs.
CVE-2025-21028
- EPSS 0.02%
- Published 03.09.2025 06:05:33
- Last modified 11.09.2025 21:22:12
Improper privilege management in ThemeManager prior to SMR Sep-2025 Release 1 allows local privileged attackers to reuse trial items.
CVE-2025-21027
- EPSS 0.02%
- Published 03.09.2025 06:05:32
- Last modified 11.09.2025 21:21:13
Improper verification of intent by broadcast receiver in ImsService prior to SMR Sep-2025 Release 1 allows local attackers to temporarily disable the SIM.
CVE-2023-21474
- EPSS 0.01%
- Published 03.09.2025 06:01:51
- Last modified 19.09.2025 20:36:06
Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.
CVE-2023-21480
- EPSS 0.03%
- Published 03.09.2025 05:17:12
- Last modified 19.09.2025 20:33:52
Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.
CVE-2023-21479
- EPSS 0.08%
- Published 03.09.2025 05:17:11
- Last modified 04.09.2025 15:36:56
Improper authorization in Smart suggestions prior to SMR Apr-2023 Release 1 in Android 13 and 4.1.01.0 in Android 12 allows remote attackers to register a schedule.
CVE-2023-21478
- EPSS 0.02%
- Published 03.09.2025 05:17:10
- Last modified 19.09.2025 20:34:05
Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.