← Back

Samsung

samsung

1,506 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Android
Nov 21, 2024
Sep 6, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper privilege management vulnerability in FolderLockNotifier in One UI Home prior to SMR Sep-2023 Release 1 allows local attackers to change some settings of the folder lock.
1Samsung
1Android
Nov 21, 2024
Sep 6, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation in Settings Suggestions prior to SMR Sep-2023 Release 1 allows attackers to launch arbitrary activity.
1Samsung
1Android
Nov 21, 2024
Sep 6, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Improper authentication in Phone and Messaging Storage SMR SEP-2023 Release 1 allows attacker to insert arbitrary data to the provider.
1Samsung
1Android
Nov 21, 2024
Sep 6, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation vulnerability in Knox AI prior to SMR Sep-2023 Release 1 allows local attackers to launch privileged activities.
1Samsung
1Android
Nov 21, 2024
Sep 6, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.
1Samsung
1Android
Nov 21, 2024
Sep 6, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper authentication in SecSettings prior to SMR Sep-2023 Release 1 allows attacker to access Captive Portal Wi-Fi in Reactivation Lock status.
1Samsung
1Android
Nov 21, 2024
Sep 6, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper input validation vulnerability in FileProviderStatusReceiver in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows local attackers to delete arbitrary files with Samsung Keyboard privilege.
1Samsung
1Android
Nov 21, 2024
Sep 6, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Improper authorization in Samsung Keyboard prior to SMR Sep-2023 Release 1 allows attacker to read arbitrary file with system privilege.
1Samsung
13Exynos 1080 Firmware
Exynos 1280 FirmwareExynos 1330 Firmware+10 more
Nov 21, 2024
Aug 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, and W920. Improper handling of PPP length parameter inconsistency ca...Show more
An issue was discovered in Samsung Exynos Mobile Processor and Wearable Processor 9810, 9610, 9820, 980, 850, 1080, 2100, 2200, 1280, 1380, 1330, 9110, and W920. Improper handling of PPP length parameter inconsistency can cause an infinite loop.Show less
1Samsung
1Syncthru Web Service
Nov 21, 2024
Aug 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue discovered in Samsung SyncThru Web Service SPL 5.93 06-09-2014 allows attackers to gain escalated privileges via MITM attacks.
1Samsung
1Sww 3400rw Firmware
Nov 21, 2024
Aug 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi
2Hp
Samsung
10231vr14a Firmware
209u7a Firmware2ky38a Firmware+1020 more
Nov 21, 2024
Aug 16, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Certain HP and Samsung Printer software packages may potentially be vulnerable to elevation of privilege due to Uncontrolled Search Path Element.
1Samsung
1Harman Infotainment
Nov 21, 2024
Aug 14, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Harman Infotainment 20190525031613 and later allows command injection via unauthenticated RPC with a D-Bus connection object.
1Samsung
1Harman Infotainment
Nov 21, 2024
Aug 14, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Harman Infotainment 20190525031613 and later discloses the IP address via CarPlay CTRL packets.
1Samsung
1Harman Infotainment
Nov 21, 2024
Aug 14, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Harman Infotainment 20190525031613 allows root access via SSH over a USB-to-Ethernet dongle with a password that is an internal project name.
1Samsung
1Galaxy Store
Nov 21, 2024
Aug 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local attackers to access privileged content providers as Galaxy Store permission.
1Samsung
1Internet
Nov 21, 2024
Aug 10, 2023
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Improper Authorization vulnerability in Samsung Internet prior to version 22.0.0.35 allows physical attacker access downloaded files in Secret Mode without user authentication.
1Samsung
1Members
Nov 21, 2024
Aug 10, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Improper URL validation vulnerability in Samsung Members prior to version 14.0.07.1 allows attackers to access sensitive information.
1Samsung
4Galaxy Book2 Go Firmware
Galaxy Book2 Pro 360 FirmwareGalaxy Book Go 5g Firmware+1 more
Nov 21, 2024
Aug 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Stack overflow vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book...Show more
Stack overflow vulnerability in SSHDCPAPP TA prior to "SAMSUNG ELECTONICS, CO, LTD. - System Hardware Update - 7/13/2023" in Windows Update for Galaxy book Go, Galaxy book Go 5G, Galaxy book2 Go and Galaxy book2 Pro 360 allows local attacker to execute arbitrary code.Show less
1Samsung
1Android
Nov 21, 2024
Aug 10, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
PendingIntent hijacking in WifiGeofenceManager prior to SMR Aug-2023 Release 1 allows local attacker to arbitrary file access.