Vulnerabilities (CVE)

Filtered by CWE-926
Total 97 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41823 2026-06-17 N/A 4.4 MEDIUM
An improper export vulnerability was reported in the Motorola Phone Extension application, that could allow a local attacker to execute unauthorized Activities. 
CVE-2023-41822 2026-06-17 N/A 4.8 MEDIUM
An improper export vulnerability was reported in the Motorola Interface Test Tool application that could allow a malicious local application to execute OS commands. 
CVE-2023-41821 2026-06-17 N/A 5.0 MEDIUM
A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information. 
CVE-2023-41816 2026-06-17 N/A 5.0 MEDIUM
An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database. 
CVE-2023-21486 1 Samsung 1 Android 2026-06-17 N/A 5.3 MEDIUM
Improper export of android application components vulnerability in ImagePreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
CVE-2023-21485 1 Samsung 1 Android 2026-06-17 N/A 5.3 MEDIUM
Improper export of android application components vulnerability in VideoPreviewActivity in Call Settings to SMR May-2023 Release 1 allows physical attackers to access some media data stored in sandbox.
CVE-2023-20962 1 Google 1 Android 2026-06-17 N/A 5.5 MEDIUM
In getSliceEndItem of MediaVolumePreferenceController.java, there is a possible way to start foreground activity from the background due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-256590210
CVE-2022-24929 1 Google 1 Android 2026-06-17 2.1 LOW 4.1 MEDIUM
Unprotected Activity in AppLock prior to SMR Mar-2022 Release 1 allows attacker to change the list of locked app without authentication.
CVE-2021-4438 1 Kyivstar 1 React Native Sms User Consent 2026-06-17 4.3 MEDIUM 5.3 MEDIUM
A vulnerability, which was classified as critical, has been found in kyivstarteam react-native-sms-user-consent up to 1.1.4 on Android. Affected by this issue is the function registerReceiver of the file android/src/main/java/ua/kyivstar/reactnativesmsuserconsent/SmsUserConsentModule.kt. The manipulation leads to improper export of android application components. Attacking locally is a requirement. Upgrading to version 1.1.5 is able to address this issue. The name of the patch is 5423dcb0cd3e4d573b5520a71fa08aa279e4c3c7. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-259508.
CVE-2021-25527 1 Samsung 1 Pay 2026-06-17 2.1 LOW 3.8 LOW
Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.
CVE-2021-25526 1 Samsung 1 Blockchain Wallet 2026-06-17 2.1 LOW 4.0 MEDIUM
Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.
CVE-2021-25400 1 Samsung 1 Internet 2026-06-17 4.6 MEDIUM 7.8 HIGH
Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
CVE-2021-25397 1 Google 1 Android 2026-06-17 2.1 LOW 6.8 MEDIUM
An improper access control vulnerability in TelephonyUI prior to SMR MAY-2021 Release 1 allows local attackers to write arbitrary files of telephony process via untrusted applications.
CVE-2021-25391 1 Google 1 Android 2026-06-17 2.1 LOW 4.0 MEDIUM
Intent redirection vulnerability in Secure Folder prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
CVE-2021-25390 1 Google 1 Android 2026-06-17 1.9 LOW 4.0 MEDIUM
Intent redirection vulnerability in PhotoTable prior to SMR MAY-2021 Release 1 allows attackers to execute privileged action.
CVE-2021-25388 1 Google 1 Android 2026-06-17 3.6 LOW 7.1 HIGH
Improper caller check vulnerability in Knox Core prior to SMR MAY-2021 Release 1 allows attackers to install arbitrary app.
CVE-2021-25379 1 Samsung 1 Gallery 2026-06-17 2.1 LOW 4.0 MEDIUM
Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.