← Back

Samsung

samsung

1,508 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Assistant
assistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,508)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Sth Eth 250 Firmware
Nov 21, 2024
Aug 23, 2018
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The v...Show more
An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process incorrectly handles the answer received from a smart camera, leading to a buffer overflow on the stack. An attacker can send a series of HTTP requests to trigger this vulnerability.Show less
1Samsung
1Sth Eth 250 Firmware
Nov 21, 2024
Aug 23, 2018
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker...Show more
On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. A strcpy overflows the destination buffer, which has a size of 40 bytes. An attacker can send an arbitrarily long "user" value in order to exploit this vulnerability.Show less
1Samsung
1Syncthru Web Service
Nov 21, 2024
Aug 3, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupView.sws for a "Print emails sent" action.
1Samsung
1Syncthru Web Service
Nov 21, 2024
Aug 3, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as demonstrated by ruiFw_pid.
2Hanwha Security
Samsung
10Hrd 1641 Firmware
Hrd 1642 FirmwareHrd 440 Firmware+7 more
Nov 21, 2024
Jun 14, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsu...Show more
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)Show less
1Samsung
1Samsung Mobile
Nov 21, 2024
May 29, 2018
N/A· v4
5.3 MEDIUM· v3
5.4 MEDIUM· v2
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for th...Show more
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.Show less
1Samsung
1Samsung Mobile
Nov 21, 2024
Mar 30, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged process, aka SVE-2017-10991.
1Samsung
1Samsung Mobile
Nov 21, 2024
Mar 30, 2018
N/A· v4
7.0 HIGH· v3
7.6 HIGH· v2
On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation of a package signature and package name, aka SVE-2017-10932.
1Samsung
1Samsung Mobile
Nov 21, 2024
Mar 30, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a crafted resolution, aka SVE-2017-11105.
1Samsung
1Samsung Mobile
Nov 21, 2024
Mar 30, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.
1Samsung
1Samsung Mobile
Nov 21, 2024
Mar 30, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privileged process via a large frame size, aka SVE-2017-11165.
1Samsung
1Display Solutions
Nov 21, 2024
Mar 6, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption during information transmission.
1Samsung
2Knox Enterprise Mobility Management
Knox Identity Access Management
Nov 21, 2024
Feb 20, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's...Show more
In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain point in the update sequence. This installed application can further leak information stored inside the Knox container to the outside world.Show less
1Samsung
1Samsung Mobile
Nov 21, 2024
Jan 4, 2018
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a brute-force attack to discover unlock inf...Show more
On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a brute-force attack to discover unlock information (PIN, password, or pattern). The Samsung ID is SVE-2017-10733.Show less
1Samsung
1Samsung Mobile
Nov 21, 2024
Jan 4, 2018
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs data to memory. The...Show more
On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs data to memory. The Samsung ID is SVE-2017-10598.Show less
1Samsung
1Internet Browser
May 13, 2026
Dec 27, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part...Show more
Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part of an MHTML file. Specifically, JavaScript code in another part of this MHTML file does not have a document.domain value corresponding to the domain that is hosting the MHTML file, but instead has a document.domain value corresponding to an arbitrary URL within the content of the MHTML file.Show less
1Samsung
1Internet Browser
May 13, 2026
Dec 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.
2Samsung
Seagate
4850 Pro Firmware
Pm851 FirmwareSt500lt015 Firmware+1 more
May 13, 2026
Nov 27, 2017
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or ThinkPad W541 laptop...Show more
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or ThinkPad W541 laptops with BIOS 2.21, or in Opal or eDrive mode on Dell Latitude E6410 laptops with BIOS A16 or Latitude E6430 laptops with BIOS A16, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by triggering a soft reset and booting from an alternative OS, aka a "Forced Restart Attack."Show less
2Samsung
Seagate
4850 Pro Firmware
Pm851 FirmwareSt500lt015 Firmware+1 more
May 13, 2026
Nov 27, 2017
N/A· v4
4.2 MEDIUM· v3
1.9 LOW· v2
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541...Show more
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2.21; Dell Latitude E6410 laptops with BIOS A16; or Latitude E6430 laptops with BIOS A16, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by leveraging failure to detect when SATA drives are unplugged in Sleep Mode, aka a "Hot Plug attack."Show less
1Samsung
4Srn 1000 Firmware
Srn 1670d FirmwareSrn 470d Firmware+1 more
May 13, 2026
Sep 11, 2017
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.