← Back

Samsung

samsung

1,506 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Android
Sep 19, 2025
Sep 3, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.
1Samsung
1Android
Sep 19, 2025
Sep 3, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.
1Samsung
1Android
Sep 19, 2025
Sep 3, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.
1Samsung
1Exynos
Sep 8, 2025
Sep 3, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Error in 3GPP specification implementation in Exynos baseband prior to SMR Apr-2023 Release 1 allows incorrect handling of unencrypted message.
1Samsung
1Android
Sep 8, 2025
Sep 3, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
PendingIntent hijacking vulnerability in CertificatePolicy in framework prior to SMR Apr-2023 Release 1 allows local attackers to access contentProvider without proper permission.
1Samsung
19Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1330 Firmware+16 more
Sep 5, 2025
Sep 2, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 54...Show more
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. A programming mistake for buffer copy leads to out-of-bounds writes via malformed ROHC packets.Show less
1Samsung
1Magician
Sep 5, 2025
Sep 2, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Magician 6.3 through 8.3 on Windows. An attacker can achieve Elevation of Privileges to SYSTEM by exploiting insecure file delete operations during the update process.
1Samsung
1Galaxy Wearable
Dec 8, 2025
Aug 6, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.
1Samsung
1Blockchain Keystore
Aug 15, 2025
Aug 6, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out-of-bounds write in drawing pinpad in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
1Samsung
1Blockchain Keystore
Aug 15, 2025
Aug 6, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out-of-bounds write in creating bitmap images in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
1Samsung
1Health
Aug 15, 2025
Aug 6, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability.
1Samsung
1Blockchain Keystore
Aug 15, 2025
Aug 6, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Out-of-bounds read in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to read out-of-bounds memory.
1Samsung
1Blockchain Keystore
Aug 15, 2025
Aug 6, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out-of-bounds write in detaching crypto box in Blockchain Keystore prior to version 1.3.17.2 allows local privileged attackers to write out-of-bounds memory.
1Samsung
1Android
Feb 24, 2026
Aug 6, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
1Samsung
1Android
Feb 24, 2026
Aug 6, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper export of android application component in Emergency SoS prior to SMR Aug-2025 Release 1 allows local attackers to access sensitive information.
1Samsung
1Android
Aug 12, 2025
Aug 6, 2025
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.
1Samsung
1Android
Aug 12, 2025
Aug 6, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control in accessing system device node prior to SMR Aug-2025 Release 1 allows local attackers to access device identifier.
1Samsung
7Exynos 1280 Firmware
Exynos 1330 FirmwareExynos 1380 Firmware+4 more
Oct 27, 2025
Aug 4, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor Exynos 2100, 1280, 2200, 1330, 1380, 1480, and 2400. A lack of a JPEG length check leads to an out-of-bound write.
1Samsung
1Data Management Server Firmware
Aug 11, 2025
Jul 29, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP ad...Show more
An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.Show less
1Samsung
1Data Management Server Firmware
Aug 11, 2025
Jul 29, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addr...Show more
An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.Show less