← Back

Samsung

samsung

1,506 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Android
Feb 10, 2025
Jun 4, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.
1Samsung
1Android
Feb 10, 2025
Jun 4, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.
1Samsung
1Android
Feb 10, 2025
Jun 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap out-of-bound write vulnerability in parsing grid image in libsavscmn.so prior to SMR June-2024 Release 1 allows local attackers to execute arbitrary code.
1Samsung
1Android
Feb 10, 2025
Jun 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Heap out-of-bound write vulnerability in parsing grid image header in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to execute arbitrary code.
1Samsung
1Android
Feb 10, 2025
Jun 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.
1Samsung
1Android
Feb 10, 2025
Jun 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files.
1Samsung
1Android
Feb 10, 2025
Jun 4, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities.
1Samsung
1Android
Feb 10, 2025
Jun 4, 2024
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.
1Samsung
1Magician
Jun 3, 2025
May 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbit...Show more
An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)Show less
1Samsung
1Magician
Jun 3, 2025
May 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already...Show more
An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)Show less
1Samsung
1Android
Jan 7, 2026
May 7, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.
1Samsung
1One Ui
Jan 7, 2026
May 7, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper authorization vulnerability in Samsung Keyboard prior to version One UI 5.1.1 allows physical attackers to partially bypass the factory reset protection.
1Samsung
1Galaxy Store
Jul 17, 2025
May 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper verification of intent by broadcast receiver vulnerability in Galaxy Store prior to version 4.5.71.8 allows local attackers to write arbitrary files with the privilege of Galaxy Store.
1Samsung
1Internet
Jul 17, 2025
May 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.
1Samsung
1Notes
Jul 17, 2025
May 7, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper input validation in Samsung Notes prior to version 4.4.15 allows local attackers to delete files with Samsung Notes privilege under certain conditions.
1Samsung
1Email
Jul 17, 2025
May 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive information.
1Samsung
1Android
Feb 10, 2025
May 7, 2024
N/A· v4
6.6 MEDIUM· v3
N/A· v2
Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.
1Samsung
1Android
Feb 10, 2025
May 7, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.
1Samsung
1Android
Feb 7, 2025
May 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.
1Samsung
1Android
Feb 10, 2025
May 7, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.