← Back

Samsung

samsung

1,506 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Samsung Internet Browser
Nov 21, 2024
Aug 5, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to access arbitrary files.
1Samsung
1Game Launcher
Nov 21, 2024
Aug 5, 2022
N/A· v4
5.0 MEDIUM· v3
N/A· v2
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction.
1Samsung
1Gameoptimizingservice
Nov 21, 2024
Aug 5, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by chan...Show more
Improper Privilege Management vulnerability in Game Optimizing Service prior to versions 3.3.04.0 in Android 10, and 3.5.04.8 in Android 11 and above allows local attacker to execute hidden function for developer by changing package name.Show less
1Samsung
1Cameralyzer
Nov 21, 2024
Aug 5, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege.
1Samsung
1Notes
Nov 21, 2024
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.
1Samsung
1Charm Firmware
Nov 21, 2024
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
PendingIntent hijacking vulnerability in cancelAlarmManager in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
1Samsung
1Charm Firmware
Nov 21, 2024
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
PendingIntent hijacking vulnerability in releaseAlarm in Charm by Samsung prior to version 1.2.3 allows local attackers to access files without permission via implicit intent.
1Samsung
1Charm
Nov 21, 2024
Aug 5, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Sensitive information exposure in onCharacteristicChanged in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.
1Samsung
1Charm
Nov 21, 2024
Aug 5, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
Sensitive information exposure in onCharacteristicRead in Charm by Samsung prior to version 1.2.3 allows attacker to get bluetooth connection information without permission.
1Samsung
1Mtower
Nov 21, 2024
Aug 4, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of service, and information disclosure by invoking the function TEE...Show more
The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of service, and information disclosure by invoking the function TEE_PopulateTransientObject with a large number in the parameter attrCount.Show less
1Samsung
1Cloud
Nov 21, 2024
Jul 12, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information.
1Samsung
1Camera
Nov 21, 2024
Jul 12, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.
1Samsung
1Android Usb Driver
Nov 21, 2024
Jul 12, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper validation of integrity check vulnerability in Samsung USB Driver Windows Installer for Mobile Phones prior to version 1.7.56.0 allows local attackers to delete arbitrary directory using directory junction.
1Samsung
1Galaxy Store
Nov 21, 2024
Jul 12, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper input validation vulnerability in BillingPackageInsraller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
1Samsung
1Galaxy Store
Nov 21, 2024
Jul 12, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper input validation vulnerability in ApexPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
1Samsung
1Galaxy Store
Nov 21, 2024
Jul 12, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper input validation vulnerability in AppsPackageInstaller in Galaxy Store prior to version 4.5.41.8 allows local attackers to launch activities as Galaxy Store privilege.
1Samsung
1Find My Mobile
Nov 21, 2024
Jul 12, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Improper identifier creation logic in Find My Mobile prior to version 7.2.24.12 allows attacker to identify the device.
1Samsung
1Samsung Gallery
Nov 21, 2024
Jul 12, 2022
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
Improper access control vulnerability in Samsung Gallery prior to version 13.1.05.8 allows physical attackers to access the pictures using S Pen air gesture.
1Samsung
1Calendar
Nov 21, 2024
Jul 12, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access calendar schedule without READ_CALENDAR permission.
1Samsung
1Smartthings
Nov 21, 2024
Jun 7, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers to add arbitrary smart devices by bypassing login activity.