← Back

Samsung

samsung

1,527 CVEs • 2,868 products

Products (2,868)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Assistant
assistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,527)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Smart Viewer
Apr 29, 2026
Aug 28, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup...Show more
Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page.Show less
1Samsung
2Ps50c7700 Television
Ps50c7700 Television Firmware
Apr 29, 2026
Jul 23, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon crash) via a long URI to TCP port 5600.
1Samsung
1Samsungdive
Apr 29, 2026
Dec 31, 2012
N/A· v4
N/A· v3
3.3 LOW· v2
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of remote tracking, which might allow physically proximate attackers to defeat a product-recovery effort...Show more
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of remote tracking, which might allow physically proximate attackers to defeat a product-recovery effort by tampering with this feature or its location data.Show less
1Samsung
1Samsungdive
Apr 29, 2026
Dec 31, 2012
N/A· v4
N/A· v3
2.9 LOW· v2
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly implement Location APIs, which allows physically proximate attackers to provide arbitrary location data via...Show more
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly implement Location APIs, which allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."Show less
2Meizu
Samsung
3Galaxy Note 2
Galaxy S2Mx
Apr 29, 2026
Dec 18, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to rea...Show more
The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memory and gain privileges via a crafted application, as demonstrated by ExynosAbuse.Show less
1Samsung
1Kies Air
Apr 29, 2026
Dec 3, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Samsung Kies Air 2.1.207051 and 2.1.210161 allows remote attackers to cause a denial of service (crash) via a crafted request to www/apps/KiesAir/jws/ssd.php.
1Samsung
1Kies Air
Apr 29, 2026
Dec 3, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitrary phone contents by spoofing or controlling the IP address.
1Samsung
1Printer Firmware
Apr 29, 2026
Nov 28, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The Samsung printer firmware before 20121031 has a hardcoded read-write SNMP community, which makes it easier for remote attackers to obtain administrative access via an SNMP request.
1Samsung
1Kies
Apr 29, 2026
Aug 24, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.12074_13_13, does not properly implement unspecified methods, which allows r...Show more
The MASetupCaller ActiveX control before 1.4.2012.508 in MASetupCaller.dll in MarkAny ContentSAFER, as distributed in Samsung KIES before 2.3.2.12074_13_13, does not properly implement unspecified methods, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a crafted HTML document.Show less
5Att
HtcSamsung+2 more
9Chacha
DesireEvo Shift 4g+6 more
Apr 29, 2026
Aug 21, 2012
N/A· v4
N/A· v3
7.1 HIGH· v2
The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Sams...Show more
The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC ChaCha, AT&T Status, HTC Desire Z, T-Mobile G2, T-Mobile myTouch 4G Slide, and Samsung Galaxy S stores touch coordinates in the dmesg buffer, which allows remote attackers to obtain sensitive information via a crafted application, as demonstrated by PIN numbers, telephone numbers, and text messages.Show less
1Samsung
1Net I Viewer
Apr 29, 2026
Aug 14, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
Samsung NET-i viewer 1.37.120316 allows remote attackers to cause a denial of service (infinite loop) via a negative size value in a TCP request to (1) NiwMasterService or (2) NiwStorageService. NOTE: some of these deta...Show more
Samsung NET-i viewer 1.37.120316 allows remote attackers to cause a denial of service (infinite loop) via a negative size value in a TCP request to (1) NiwMasterService or (2) NiwStorageService. NOTE: some of these details are obtained from third party information.Show less
1Samsung
1Net I Viewer
Apr 29, 2026
Aug 14, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE:...Show more
The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.Show less
1Samsung
1Net I Viewer
Apr 29, 2026
Aug 14, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary co...Show more
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary code via a long string in the fname parameter. NOTE: some of these details are obtained from third party information.Show less
1Samsung
1D6000 Firmware
Apr 29, 2026
Aug 14, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
The Samsung D6000 TV and possibly other products allows remote attackers to cause a denial of service (crash) via a long string in certain fields, as demonstrated by the MAC address field, possibly a buffer overflow.
1Samsung
1D6000 Firmware
Apr 29, 2026
Aug 14, 2012
N/A· v4
N/A· v3
7.8 HIGH· v2
The Samsung D6000 TV and possibly other products allow remote attackers to cause a denial of service (continuous restart) via a crafted controller name.
1Samsung
1Net I Viewer
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewer 1.37 allows remote attackers to execute arbitrary code via a long str...Show more
Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewer 1.37 allows remote attackers to execute arbitrary code via a long string in the first argument.Show less
3Acer
GoogleSamsung
6Ac700 Chromebook
Chrome OsChromebox 3+3 more
Apr 29, 2026
Jun 7, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 20.0.1132.22 on the Acer AC700; Samsung Series 5, 5 550, and Chromebox 3; and Cr-48 Chromebook platforms have unknown impact and attack vectors.
3Acer
GoogleSamsung
4Ac700 Chromebook
Chrome OsCr 48 Chromebook+1 more
Apr 29, 2026
Feb 29, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.60 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
3Acer
GoogleSamsung
4Ac700 Chromebook
Chrome OsCr 48 Chromebook+1 more
Apr 29, 2026
Jan 12, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.
3Acer
GoogleSamsung
4Ac700 Chromebook
Chrome OsCr 48 Chromebook+1 more
Apr 29, 2026
Dec 9, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.63 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.