CWE-926

Total CVEs
27
Vulnerabilities
Avg CVSS v3
4.8
Medium
Avg CVSS v2
2.7
Low
Latest CVE
2025
Most Recent

Severity Distribution

Critical 0
0%
High 3
11.1%
Medium 18
66.7%
Low 6
22.2%

External References

All CVEs (27)

Page 1 of 2
CVSS:7.8(High)

Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.

CVSS:7.1(High)

Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.

CVSS:6.5(Medium)

The com.enflick.android.TextNow (aka TextNow: Call + Text Unlimited) application 24.17.0.2 for Android enables any installed application (with no permissions) to place phone calls without user interac...

CVSS:6.3(Medium)

The vulnerability is an intent redirection in LG ThinQ Service ("com.lge.lms2") in the "com/lge/lms/things/ui/notification/NotificationManager.java" file. This vulnerability could be exploited by a th...

CVSS:5.5(Medium)

Improper access control in Sticker Center prior to SMR Apr-2025 Release 1 allows local attackers to access image files with system privilege.

CVSS:5.5(Medium)

In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local informatio...

CVSS:5.5(Medium)

Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.

CVSS:5.5(Medium)

An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.

CVSS:5.3(Medium)

A vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function registerReceiver of the f...

CVSS:5.1(Medium)

An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI.

CVSS:5.0(Medium)

An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization.

CVSS:5.0(Medium)

A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.

CVSS:5.0(Medium)

An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database.

CVSS:4.8(Medium)

An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands.

CVSS:4.6(Medium)

Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox...

CVSS:4.6(Medium)

Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox...

CVSS:4.4(Medium)

An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities.

CVSS:4.0(Medium)

Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

CVSS:4.0(Medium)

Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.

CVSS:3.3(Low)

The vulnerability is that the Messaging ("com.android.mms") app patched by LG forwards attacker-controlled intents back to the attacker in the exported "com.android.mms.ui.QClipIntentReceiverActivity"...

CVSS:3.3(Low)

The vulnerability allows an unprivileged(untrusted) third-party application to interact with a content-provider unsafely exposed by the Android Agent application, potentially modifying sensitive setti...

CVSS:3.3(Low)

Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.

CVSS:3.3(Low)

Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.

CVSS:3.3(Low)

Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.