Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:NSamsung Android
OSSamsung11.012.013.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path Traversal
Related vulnerabilities
CVE-2025-21043HIGH8.8⚠ KEVsame product
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execu...
CVE-2025-21042HIGH8.8⚠ KEVsame product
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execu...
CVE-2021-25487HIGH7.3⚠ KEVsame product
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Releas...
CVE-2026-21064HIGH7.0same product
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inope...
CVE-2026-21068HIGH8.4same product
Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers...