← Back

Samsung

samsung

1,508 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Assistant
assistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,508)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Samsung Pass
Nov 21, 2024
Jun 7, 2022
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Improper authorization in Samsung Pass prior to 1.0.00.33 allows physical attackers to acess account list without authentication.
1Samsung
1Galaxy S22 Firmware
Nov 21, 2024
May 3, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy...Show more
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.Show less
1Samsung
1Gear Iconx Pc Manager
Nov 21, 2024
May 3, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
DLL hijacking vulnerability in Gear IconX PC Manager prior to version 2.1.220405.51 allows attacker to execute arbitrary code. The patch adds proper absolute path to prevent dll hijacking.
1Samsung
1Galaxy Store
Nov 21, 2024
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to exi...Show more
Improper input validation vulnerability in InstallAgent in Galaxy Store prior to version 4.5.41.8 allows attacker to overwrite files stored in a specific path. The patch adds proper protection to prevent overwrite to existing files.Show less
1Samsung
1Link To Windows Service
Nov 21, 2024
May 3, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper authentication in Link to Windows Service prior to version 2.3.04.1 allows attacker to lock the device. The patch adds proper caller signature check logic.
1Samsung
1Voice Note
Nov 21, 2024
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Unprotected activities in Voice Note prior to version 21.3.51.11 allows attackers to record voice without user interaction. The patch adds proper permission for vulnerable activities.
1Samsung
1Android Usb Driver Windows Installer
Nov 21, 2024
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code.
1Samsung
1Samsung Security Supporter
Nov 21, 2024
Apr 11, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0 allows attacker to set the arbitrary folder as Secret Folder without Samsung Security Supporter permission
1Samsung
1Members
Nov 21, 2024
Apr 11, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local attacker to execute call function without CALL_PHONE permission.
1Samsung
1Galaxy Store
Nov 21, 2024
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without user interactions.
1Samsung
1Samsung Flow
Nov 21, 2024
Apr 11, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker to write the file without Samsung Flow permission.
1Samsung
1Galaxy Store
Nov 21, 2024
Apr 11, 2022
N/A· v4
5.5 MEDIUM· v3
5.0 MEDIUM· v2
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.
1Samsung
1Samsung Flow
Nov 21, 2024
Apr 11, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission.
1Samsung
1Galaxy Store
Nov 21, 2024
Apr 11, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.
1Samsung
1Update
Nov 21, 2024
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.
1Samsung
1Kies
Nov 21, 2024
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.
1Samsung
1Smart Switch Pc
Nov 21, 2024
Apr 11, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.
1Samsung
1Samsung Pass
Nov 21, 2024
Apr 11, 2022
N/A· v4
4.3 MEDIUM· v3
1.9 LOW· v2
Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication
1Samsung
1Recovery
Nov 21, 2024
Apr 11, 2022
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsungRecovery permission.
1Samsung
1Internet
Nov 21, 2024
Apr 11, 2022
N/A· v4
4.0 MEDIUM· v3
4.3 MEDIUM· v2
Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.