← Back

Samsung

samsung

1,506 CVEs • 2,866 products

Products (2,866)

Click to collapse
Toggle
Android
android
Notes
notes
X14j Firmware
x14j_firmware
Galaxy Store
galaxy_store
Internet
internet
Account
account
Escargot
escargot
Wear Os
wear_os
Smartthings
smartthings
Members
members
Mtower
mtower
Smart Switch
smart_switch
Kies
kies
Health
health
Pass
pass
Email
email
Magician
magician
Cloud
cloud
Gallery
gallery
One
one
Camera
camera
Flow
flow
Samsung Email
samsung_email
Tizenrt
tizenrt
Group Sharing
group_sharing
Samsung Pass
samsung_pass
Quick Share
quick_share
Calendar
calendar
Net I Viewer
net-i_viewer
Smartviewer
smartviewer
Knox
knox
Galaxy Apps
galaxy_apps
Exynos
exynos
Samsung Flow
samsung_flow
Samsung Pay
samsung_pay
Myfiles
myfiles
Sassistant
sassistant
Rlottie
rlottie
Smart Viewer
smart_viewer

CVEs (1,506)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Samsung
1Android
Nov 21, 2024
Jul 6, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Improper access control vulnerability in PersonaManagerService prior to SMR Jul-2023 Release 1 allows local attackers to change confiugration.
1Samsung
1Searchwidget
Nov 21, 2024
Jun 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper access control vulnerability in SearchWidget prior to version 3.3 in China models allows untrusted applications to start arbitrary activity.
1Samsung
1Exynos
Nov 21, 2024
Jun 28, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Heap out-of-bound write vulnerability in Exynos baseband prior to SMR Jun-2023 Release 1 allows remote attacker to execute arbitrary code.
1Samsung
1Android
Dec 5, 2024
Jun 28, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condit...Show more
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.Show less
1Samsung
1Android
Nov 21, 2024
Jun 28, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
Improper Knox ID validation logic in notification framework prior to SMR Jun-2023 Release 1 allows local attackers to read work profile notifications without proper access permission.
1Samsung
2Exynos 5123 Firmware
Exynos 5300 Firmware
Jan 7, 2025
Jun 7, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended querying of RCS capability via a crafted application.
1Samsung
2Exynos 5123 Firmware
Exynos 5300 Firmware
Jan 7, 2025
Jun 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause changes to the activation mode of RCS via a crafted application.
1Samsung
2Exynos 5123 Firmware
Exynos 5300 Firmware
Jan 7, 2025
Jun 7, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. Incorrect resource transfer between spheres can cause unintended querying of the SIM status via a crafted application.
1Samsung
1Galaxy Store
Nov 21, 2024
May 26, 2023
N/A· v4
9.6 CRITICAL· v3
N/A· v2
XSS vulnerability from InstantPlay in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
1Samsung
1Galaxy Store
Nov 21, 2024
May 26, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
InstantPlay which included vulnerable script which could execute javascript in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
1Samsung
1Galaxy Store
Nov 21, 2024
May 26, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper scheme validation from InstantPlay Deeplink in Galaxy Store prior to version 4.5.49.8 allows attackers to execute javascript API to install APK from Galaxy Store.
1Samsung
4Exynos 1080 Firmware
Exynos 5123 FirmwareExynos 5300 Firmware+1 more
Jan 28, 2025
May 9, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue was discovered in Exynos Mobile Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, and Exynos 1080. Binding of a wrong resource can occur due to improper handling of parameters while bindi...Show more
An issue was discovered in Exynos Mobile Processor and Modem for Exynos Modem 5123, Exynos Modem 5300, Exynos 980, and Exynos 1080. Binding of a wrong resource can occur due to improper handling of parameters while binding a network interface.Show less
1Samsung
1Samsung Blockchain Keystore
Nov 21, 2024
May 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds Read vulnerability while processing CMD_COLDWALLET_BTC_SET_PRV_UTXO in bc_core trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
1Samsung
1Samsung Blockchain Keystore
Nov 21, 2024
May 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
1Samsung
1Samsung Blockchain Keystore
Nov 21, 2024
May 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_UPDATE_SCREEN in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
1Samsung
1Samsung Blockchain Keystore
Nov 21, 2024
May 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.
1Samsung
1Samsung Blockchain Keystore
Nov 21, 2024
May 4, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Out-of-bounds Read vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to read arbitrary memory.
1Samsung
1Samsung Blockchain Keystore
Nov 21, 2024
May 4, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code...Show more
Out-of-bounds Write vulnerability while processing BC_TUI_CMD_SEND_RESOURCE_DATA_ARRAY command in bc_tui trustlet from Samsung Blockchain Keystore prior to version 1.3.12.1 allows local attacker to execute arbitrary code.Show less
1Samsung
1Samsung Core Services
Nov 21, 2024
May 4, 2023
N/A· v4
8.6 HIGH· v3
N/A· v2
Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to write arbitrary file in sandbox.
1Samsung
1Android
Nov 21, 2024
May 4, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Potential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackers to cause invalid memory access.