← Back

Samsung

samsung

1,527 CVEs • 2,868 products

Products (2,868)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Assistant
assistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,527)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
2Galaxy App
Samsung Account App
May 13, 2026
Mar 27, 2017
N/A· v4
8.0 HIGH· v3
7.9 HIGH· v2
GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obtain sensitive information and execute arbitrary code.
1Samsung
6M288ofw Firmware
Nt14u FirmwareX10p Firmware+3 more
May 13, 2026
Mar 23, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, which makes it easier for remote attackers to obtain sensitive information...Show more
The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, which makes it easier for remote attackers to obtain sensitive information or bypass authentication via a brute-force attack.Show less
1Samsung
1Samsung Mobile
May 13, 2026
Mar 23, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers to have unspecified impact via unknown vec...Show more
The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers to have unspecified impact via unknown vectors, which trigger an out-of-bounds read, aka SVE-2016-6362.Show less
5Allwinner
AmdIntel+2 more
20A64
Athlon Ii 640 X4Atom C2750+17 more
May 13, 2026
Feb 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possib...Show more
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.Show less
5Allwinner
AmdIntel+2 more
20A64
Athlon Ii 640 X4Atom C2750+17 more
May 13, 2026
Feb 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possib...Show more
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.Show less
5Allwinner
AmdIntel+2 more
20A64
Athlon Ii 640 X4Atom C2750+17 more
May 13, 2026
Feb 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is poss...Show more
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.Show less
1Samsung
1Samsung Mobile
May 13, 2026
Feb 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.
1Samsung
1Samsung Mobile
May 13, 2026
Feb 13, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a service call.
1Samsung
1Samsung Mobile
May 13, 2026
Feb 1, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/msm/camera_v2/sensor/msm_sensor.c in Samsung devices with Android KK(4.4) or L and an APQ8084, MSM89...Show more
Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/msm/camera_v2/sensor/msm_sensor.c in Samsung devices with Android KK(4.4) or L and an APQ8084, MSM8974, or MSM8974pro chipset allows local users to have unspecified impact via the gpio_config.gpio_name value.Show less
1Samsung
1Exynos Fimg2d
May 13, 2026
Jan 30, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
NULL pointer dereference in Samsung Exynos fimg2d driver for Android L(5.0/5.1) and M(6.0) allows attackers to have unspecified impact via unknown vectors. The Samsung ID is SVE-2016-6382.
1Samsung
1Knox
May 13, 2026
Jan 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a crafted application.
1Samsung
1Knox
May 13, 2026
Jan 27, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service.
1Samsung
1Knox
May 13, 2026
Jan 27, 2017
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack.
1Samsung
1Exynos Fimg2d Driver
May 13, 2026
Jan 18, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6...Show more
Use-after-free vulnerability in the Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows attackers to obtain sensitive information via unspecified vectors. The Samsung ID is SVE-2016-6853.Show less
1Samsung
1Exynos Fimg2d Driver
May 13, 2026
Jan 18, 2017
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736.
1Samsung
1Samsung Mobile
May 13, 2026
Jan 18, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The SmartCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed serializab...Show more
The SmartCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed serializable object.Show less
1Samsung
1Samsung Mobile
May 13, 2026
Jan 18, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The SpamCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed serializabl...Show more
The SpamCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly gain privileges via a malformed serializable object.Show less
1Samsung
1Samsung Mobile
May 6, 2026
Jan 12, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Samsung Note devices with KK(4.4), L(5.0/5.1), and M(6.0) software allow attackers to crash the system by creating an arbitrarily large number of active VR service threads. The Samsung ID is SVE-2016-7650.
1Samsung
1Samsung Mobile
May 6, 2026
Jan 12, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allow attackers to crash systemUI by leveraging incomplete exception handling. The Samsung ID is SVE-2016-7122.
1Samsung
1Samsung Mobile
May 6, 2026
Jan 9, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS. The zero-permission app...Show more
Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS. The zero-permission app will create an active install session for a separate app that it has embedded within it. The active install session of the embedded app is performed using the android.content.pm.PackageInstaller class and its nested classes in the Android API. The active install session will write the embedded APK file to the /data/app directory, but the app will not be installed since third-party applications cannot programmatically install apps. Samsung has modified AOSP in order to accelerate the parsing of APKs by introducing the com.android.server.pm.PackagePrefetcher class and its nested classes. These classes will parse the APKs present in the /data/app directory and other directories, even if the app is not actually installed. The embedded APK that was written to the /data/app directory via the active install session has a very large but valid AndroidManifest.xml file. Specifically, the AndroidManifest.xml file contains a very large string value for the name of a permission-tree that it declares. When system_server tries to parse the APK file of the embedded app from the active install session, it will crash due to an uncaught error (i.e., java.lang.OutOfMemoryError) or an uncaught exception (i.e., std::bad_alloc) because of memory constraints. The Samsung Android device will encounter a soft reboot due to a system_server crash, and this action will keep repeating since parsing the APKs in the /data/app directory as performed by the system_server process is part of the normal boot process. The Samsung ID is SVE-2016-6917.Show less