← Back

Samsung

samsung

1,506 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Android
Mar 25, 2025
Feb 4, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.
1Samsung
1Android
Mar 25, 2025
Feb 4, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out-of-bounds write in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to cause memory corruption.
1Samsung
1Android
Feb 12, 2025
Feb 4, 2025
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper access control in Samsung Message prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
1Samsung
1Android
Feb 12, 2025
Feb 4, 2025
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper access control in SoundPicker prior to SMR Jan-2025 Release 1 allows physical attackers to access data across multiple user profiles.
1Samsung
1Android
Feb 12, 2025
Feb 4, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggerin...Show more
Out-of-bounds write in accessing uninitialized memory for svc1td in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.Show less
1Samsung
1Android
Feb 12, 2025
Feb 4, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for t...Show more
Out-of-bounds write in accessing buffer storing the decoded video frames in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to execute arbitrary code with privilege. User interaction is required for triggering this vulnerability.Show less
1Samsung
17Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1330 Firmware+14 more
Jun 20, 2025
Jan 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400. UE does not limit the number of...Show more
An issue was discovered in Samsung Mobile Processor and Modem Exynos 9820, 9825, 980, 990, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W1000, Modem 5123, Modem 5300, Modem 5400. UE does not limit the number of attempts for the RRC Setup procedure in the 5G SA, leading to a denial of service (battery-drain attack).Show less
1Samsung
8Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 2100 Firmware+5 more
Jun 20, 2025
Jan 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to a stack out-of-bounds write at loadInputBuffers.
1Samsung
19Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1330 Firmware+16 more
Jun 20, 2025
Jan 13, 2025
N/A· v4
4.3 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, and Modem 5300. Th...Show more
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 9820, 9825, 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 9110, W920, W930, W1000, Modem 5123, and Modem 5300. The UE incorrectly handles a malformed uplink scheduling message, resulting in an information leak of the UE.Show less
1Samsung
8Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 2100 Firmware+5 more
Jun 20, 2025
Jan 13, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Mobile Processor Exynos 9820, 9825, 980, 990, 850, 1080, 2100, and 1280. Lack of a length check leads to a stack out-of-bounds write at loadOutputBuffers.
1Samsung
1Android
Feb 2, 2026
Dec 31, 2024
N/A· v4
3.9 LOW· v3
N/A· v2
Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnera...Show more
Protection Mechanism Failure in bootloader prior to SMR Oct-2024 Release 1 allows physical attackers to reset lockscreen failure count by hardware fault injection. User interaction is required for triggering this vulnerability.Show less
1Samsung
1Magician
Jun 3, 2025
Dec 3, 2024
N/A· v4
2.8 LOW· v3
N/A· v2
An issue was discovered in the installer in Samsung Magician 8.1.0 on Windows. An attacker can create arbitrary folders in the system permission directory via a symbolic link during the installation process.
1Samsung
1Quick Share
Sep 24, 2025
Dec 3, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.
1Samsung
1Smart Touch Call
Jan 9, 2026
Dec 3, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Use of implicit intent for sensitive communication in Smart Touch Call prior to 1.0.0.8 allows local attackers to launch privileged activities. User interaction is required for triggering this vulnerability.
1Samsung
1Smartthings
Jul 17, 2025
Dec 3, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Use of implicit intent for sensitive communication in SmartThings prior to version 1.8.21 allows local attackers to get sensitive information.
1Samsung
1Android
Feb 10, 2025
Dec 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Out-of-bound write in libsaped.so prior to SMR Dec-2024 Release 1 allows remote attackers to execute arbitrary code.
1Samsung
1Android
Feb 10, 2025
Dec 3, 2024
N/A· v4
2.4 LOW· v3
N/A· v2
Authentication Bypass Using an Alternate Path in Dex Mode prior to SMR Dec-2024 Release 1 allows physical attackers to temporarily access to recent app list.
1Samsung
1Android
Feb 10, 2025
Dec 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.
1Samsung
1Android
Feb 10, 2025
Dec 3, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Path Traversal in ThemeCenter prior to SMR Dec-2024 Release 1 allows physical attackers to copy apk files to arbitrary path with ThemeCenter privilege.
1Samsung
1Android
Feb 10, 2025
Dec 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds write in libswmfextractor.so prior to SMR Dec-2024 Release 1 allows local attackers to execute arbitrary code.