← Back

Samsung

samsung

1,506 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Magicinfo 9 Server
Jul 30, 2025
Jul 23, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
1Samsung
1Magicinfo 9 Server
Jul 30, 2025
Jul 23, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less...Show more
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.This issue affects MagicINFO 9 Server: less than 21.1080.0Show less
1Samsung
1Android
Jul 10, 2025
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
1Samsung
1Android
Jul 10, 2025
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
1Samsung
1Android
Jul 15, 2025
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.
1Samsung
1Android
Jul 15, 2025
Jul 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.
1Samsung
1Android
Jul 15, 2025
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.
1Samsung
1Wear Os
Jan 20, 2026
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.
1Samsung
1Android
Jul 16, 2025
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.
1Samsung
1Android
Jul 16, 2025
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.
1Samsung
1Android
Jul 14, 2025
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.
1Samsung
1Android
Jul 14, 2025
Jul 8, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.
1Samsung
1Android
Jul 14, 2025
Jul 8, 2025
N/A· v4
2.1 LOW· v3
N/A· v2
Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.
1Samsung
1Wear Os
Jan 20, 2026
Jul 8, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.
1Samsung
1Wear Os
Jan 20, 2026
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.
1Samsung
1Android
Jul 14, 2025
Jul 8, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
1Samsung
1Android
Jul 14, 2025
Jul 8, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.
1Samsung
19Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1330 Firmware+16 more
Oct 27, 2025
Jul 7, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400, the lack of a...Show more
In RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 9110, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400, the lack of a length check leads to out-of-bounds writes.Show less
1Samsung
2Exynos 2400 Firmware
Modem 5400 Firmware
Oct 27, 2025
Jul 7, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in L2 in Samsung Mobile Processor and Modem Exynos 2400 and Modem 5400. The lack of a length check leads to a Denial of Service via a malformed PDCP packet.
1Samsung
1Rlottie
Jul 3, 2025
Jun 30, 2025
5.1 MEDIUM· v4
9.8 CRITICAL· v3
N/A· v2
Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.