← Back

Samsung

samsung

1,506 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Editor Lite
Nov 21, 2024
Sep 9, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control vulnerability in Editor Lite prior to version 4.0.40.14 allows attackers to access sensitive information.
1Samsung
1Group Sharing
Nov 21, 2024
Sep 9, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
1Samsung
1Group Sharing
Nov 21, 2024
Sep 9, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to access device information.
1Samsung
1Samsung Email
Nov 21, 2024
Sep 9, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.
1Samsung
1Smarttagplugin
Nov 21, 2024
Sep 9, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.21-6 allows privileged attackers to trigger a XSS on a victim's devices.
2Google
Samsung
2Android
Photo Editor
Nov 21, 2024
Sep 9, 2022
N/A· v4
2.4 LOW· v3
N/A· v2
Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows physical attackers to read internal application data.
1Samsung
1Samsung Pass
Nov 21, 2024
Sep 9, 2022
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
1Samsung
1Tizenrt
Nov 21, 2024
Sep 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
1Samsung
1Tizenrt
Nov 21, 2024
Sep 8, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a missing sqlite3_close after sqlite3_open_v2, leading to a denial of serv...Show more
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a missing sqlite3_close after sqlite3_open_v2, leading to a denial of service.Show less
1Samsung
1Mtower
Nov 21, 2024
Sep 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coordinates, leading to a denial of service.
1Samsung
1Mtower
Nov 21, 2024
Sep 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new.
1Samsung
1Mtower
Nov 21, 2024
Sep 5, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading to a denial of service.
1Samsung
1Mtower
Nov 21, 2024
Sep 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.
1Samsung
1Mtower
Nov 21, 2024
Sep 1, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject.
1Samsung
1Mtower
Nov 21, 2024
Aug 11, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numaker-PFM-M2351 TEE kernel crash.
1Samsung
1Update
Nov 21, 2024
Aug 5, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
DLL hijacking vulnerability in Samsung Update Setup prior to version 2.2.9.50 allows attackers to execute arbitrary code.
1Samsung
1Checkout
Nov 21, 2024
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
SQL injection vulnerability via IAPService in Samsung Checkout prior to version 5.0.53.1 allows attackers to access IAP information.
1Samsung
1Galaxy Wearable
Nov 21, 2024
Aug 5, 2022
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Implicit Intent hijacking vulnerability in Galaxy Wearable prior to version 2.2.50 allows attacker to get sensitive information.
1Samsung
1Samsung Email
Nov 21, 2024
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Intent redirection vulnerability using implicit intent in Samsung email prior to version 6.1.70.20 allows attacker to get sensitive information.
1Samsung
1Charm Firmware
Nov 21, 2024
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Unprotected provider vulnerability in Charm by Samsung prior to version 1.2.3 allows attackers to read connection state without permission.