← Back

Samsung

samsung

1,506 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Android
Nov 21, 2024
Jan 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
1Samsung
1Dex
Nov 21, 2024
Jan 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-user environment.
1Samsung
7Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1380 Firmware+4 more
May 22, 2025
Dec 13, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A race condition issue discovered in Samsung Mobile Processor Exynos 9820, 980, 1080, 2100, 2200, 1280, and 1380 allows unintended modifications of values within certain areas.
1Samsung
9Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1330 Firmware+6 more
Nov 21, 2024
Dec 13, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Samsung Mobile Processor and Wearable Processor (Exynos 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, and W920) allow Information Disclosure in the Bootloader.
1Samsung
7Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1380 Firmware+4 more
Nov 21, 2024
Dec 13, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.
1Samsung
1Escargot
Nov 21, 2024
Dec 6, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: from 3.0.0 through 4.0.0.
1Samsung
1Galaxy Store
Nov 21, 2024
Dec 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.
1Samsung
1Galaxy Store
Nov 21, 2024
Dec 5, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK from Galaxy Store.
1Samsung
1Samsung Keyboard
Nov 21, 2024
Dec 5, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Andro...Show more
Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5, 5.5.00.58 in Android 12, and 5.6.00.52, 5.6.10.42, 5.7.00.45 in Android 13 allows adjacent attackers to access keystroke data using Man-in-the-Middle attack.Show less
1Samsung
1Cloud
Nov 21, 2024
Dec 5, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to access location information without permission.
1Samsung
1Samsung Voice Recorder
Nov 21, 2024
Dec 5, 2023
N/A· v4
2.4 LOW· v3
N/A· v2
Improper Access Control in Samsung Voice Recorder prior to versions 21.4.15.01 in Android 12 and Android 13, 21.4.50.17 in Android 14 allows physical attackers to access Voice Recorder information on the lock screen.
1Samsung
1Pass
Nov 21, 2024
Dec 5, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid exception handler.
1Samsung
1Pass
Nov 21, 2024
Dec 5, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid flag setting.
1Samsung
1Gamehomecn
Nov 21, 2024
Dec 5, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control vulnerablility in GameHomeCN prior to version 4.2.60.2 allows local attackers to launch arbitrary activity in GameHomeCN.
1Samsung
1Search Widget
Nov 21, 2024
Dec 5, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
PendingIntent hijacking vulnerability in Search Widget prior to version 3.4 in China models allows local attackers to access data.
1Samsung
1Account Web Software Development Kit
Nov 21, 2024
Dec 5, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Implicit intent hijacking vulnerability in Samsung Account Web SDK prior to version 1.5.24 allows attacker to get sensitive information.
1Samsung
1Find My Mobile
Nov 21, 2024
Dec 5, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Abuse of remote unlock in Find My Mobile prior to version 7.3.13.4 allows physical attacker to unlock the device remotely by resetting the Samsung Account password with SMS verification when user lost the device.
1Samsung
1Android
Nov 21, 2024
Dec 5, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in KnoxCustomManagerService prior to SMR Dec-2023 Release 1 allows attacker to access device SIM PIN.
1Samsung
1Android
Nov 21, 2024
Dec 5, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Improper authorization verification vulnerability in AR Emoji prior to SMR Dec-2023 Release 1 allows attackers to read sandbox data of AR Emoji.
1Samsung
1Android
Nov 21, 2024
Dec 5, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper access control vulnerability in SmartManagerCN prior to SMR Dec-2023 Release 1 allows local attackers to access arbitrary files with system privilege.