Samsung
samsung
1,508 CVEs • 2,866 products
Products (2,866)
Click to collapseToggle
Products (2,866)
Click to collapse
CVEs (1,508)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 23, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The v...Show more |
1Samsung 1Sth Eth 250 Firmware Nov 21, 2024 Aug 23, 2018 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker...Show more |
Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupView.sws for a "Print emails sent" action. |
1Samsung 1Syncthru Web Service Nov 21, 2024 Aug 3, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as demonstrated by ruiFw_pid. |
2Hanwha Security Samsung10Hrd 1641 Firmware Hrd 1642 FirmwareHrd 440 Firmware+7 moreNov 21, 2024 Jun 14, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsu...Show more |
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for th...Show more |
On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged process, aka SVE-2017-10991. |
On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation of a package signature and package name, aka SVE-2017-10932. |
On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a crafted resolution, aka SVE-2017-11105. |
On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747. |
On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privileged process via a large frame size, aka SVE-2017-11165. |
Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption during information transmission. |
1Samsung 2Knox Enterprise Mobility Management Knox Identity Access ManagementNov 21, 2024 Feb 20, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's...Show more |
On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a brute-force attack to discover unlock inf...Show more |
On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs data to memory. The...Show more |
Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information, via vectors involving an IFRAME element inside XSLT data in one part...Show more |
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property. |
2Samsung Seagate4850 Pro Firmware Pm851 FirmwareSt500lt015 Firmware+1 moreMay 13, 2026 Nov 27, 2017 N/A· v4 4.2 MEDIUM· v3 1.9 LOW· v2 Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or ThinkPad W541 laptop...Show more |
2Samsung Seagate4850 Pro Firmware Pm851 FirmwareSt500lt015 Firmware+1 moreMay 13, 2026 Nov 27, 2017 N/A· v4 4.2 MEDIUM· v3 1.9 LOW· v2 Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541...Show more |
1Samsung 4Srn 1000 Firmware Srn 1670d FirmwareSrn 470d Firmware+1 moreMay 13, 2026 Sep 11, 2017 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter. |