← Back

Samsung

samsung

1,506 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Magicinfo 9 Server
Nov 3, 2025
May 13, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
1Samsung
1Notes
Jul 16, 2025
May 7, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerab...Show more
Use of implicit intent for sensitive communication in translation in Samsung Notes prior to version 4.4.29.23 allows local attackers to get sensitive information. User interaction is required for triggering this vulnerability.Show less
1Samsung
1Notes
Jul 17, 2025
May 7, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Out-of-bounds read in applying binary of text content in Samsung Notes prior to version 4.4.29.23 allows attackers to read out-of-bounds memory.
1Samsung
1Flow
Jul 16, 2025
May 7, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper verification of intent by broadcast receiver in Samsung Flow prior to version 4.9.17.6 allows local attackers to modify Samsung Flow configuration.
1Samsung
1Flow
Jul 16, 2025
May 7, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation in Samsung Flow prior to version 4.9.17.6 allows local attackers to access data within Samsung Flow.
1Samsung
1Gallery
Jan 30, 2026
May 7, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows local attackers to access data within Samsung Gallery.
1Samsung
1Gallery
Jan 30, 2026
May 7, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows remote attackers to access data and perform internal operation...Show more
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows remote attackers to access data and perform internal operations within Samsung Gallery.Show less
1Samsung
1Gallery
Jan 30, 2026
May 7, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows attackers to read and write arbitrary file with the privilege...Show more
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows attackers to read and write arbitrary file with the privilege of Samsung Gallery.Show less
1Samsung
1Gallery
Jan 30, 2026
May 7, 2025
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profile...Show more
Improper access control in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows physical attackers to access data across multiple user profiles.Show less
1Samsung
1Bixby
Jul 18, 2025
May 7, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.
1Samsung
1Android
May 21, 2025
May 7, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.
1Samsung
1Android
May 21, 2025
May 7, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.
1Samsung
1Android
May 21, 2025
May 7, 2025
N/A· v4
4.0 MEDIUM· v3
N/A· v2
Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.
1Samsung
1Android
May 21, 2025
May 7, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.
1Samsung
1Android
May 21, 2025
May 7, 2025
N/A· v4
3.3 LOW· v3
N/A· v2
Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.
1Samsung
1Android
May 21, 2025
May 7, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.
1Samsung
1Android
May 21, 2025
May 7, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.
1Samsung
1Android
May 21, 2025
May 7, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.
1Samsung
1Wear Os
Jan 15, 2026
May 7, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper export of android application components in Settings in Galaxy Watch prior to SMR May-2025 Release 1 allows physical attackers to access developer settings.
1Samsung
1Android
May 21, 2025
May 7, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.