Vulnerability index

Browse CVEs

727 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Samsung Mobile HIGH 7.8
CVE-2018-9141

On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a c…

Mitigation only
Fix from $1,950 2018-03-30
Samsung Mobile HIGH 7.0
CVE-2018-9142

On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation…

Mitigation only
Fix from $1,950 2018-03-30
Samsung Mobile MEDIUM 6.1
CVE-2018-9140

On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribut…

Mitigation only
Fix from $1,600 2018-03-30
Knox Enterprise Mobility Management MEDIUM 5.9
CVE-2017-10963

In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker c…

Mitigation only
Fix from $1,600 2018-02-20
Samsung Mobile HIGH 8.4
CVE-2017-18020

On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader becaus…

Mitigation only
Fix from $1,950 2018-01-04
Samsung Mobile HIGH 8.1
CVE-2018-5210

On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code exe…

Mitigation only
Fix from $1,950 2018-01-04
Internet Browser MEDIUM 6.1
CVE-2017-17859

Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information…

Mitigation only
Fix from $1,600 2017-12-27
Internet Browser HIGH 7.5
CVE-2017-17692EPSS 79%

Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript co…

No fix yet
Fix from $1,950 2017-12-21
Srn 1670d Firmware HIGH 8.1
CVE-2017-14262

On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, …

Mitigation only
Fix from $1,950 2017-09-11
Galaxy S4 Firmware CRITICAL 9.8
CVE-2015-1801

The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory cor…

Mitigation only
Fix from $2,300 2017-08-24
Galaxy S4 Firmware HIGH 7.5
CVE-2015-1800

The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive informat…

No fix yet
Fix from $1,950 2017-08-24
Samsung Mobile MEDIUM 6.5
CVE-2015-7896EPSS 7%

LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via…

No fix yet
Fix from $1,600 2017-08-24
Galaxy S6 Edge Firmware HIGH 8.8
CVE-2015-7894EPSS 9%

The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a…

No fix yet
Fix from $1,950 2017-08-09
Samsung Mobile HIGH 7.0
CVE-2015-7891

Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows loca…

No fix yet
Fix from $1,950 2017-08-02
Samsung Mobile MEDIUM 5.5
CVE-2015-7895

Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

No fix yet
Fix from $1,600 2017-06-27
Samsung Mobile MEDIUM 5.5
CVE-2015-7898

Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

No fix yet
Fix from $1,600 2017-06-27
Magician HIGH 8.8
CVE-2017-3218

Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for softw…

Mitigation only
Fix from $1,950 2017-06-21
Galaxy S6 Edge Firmware HIGH 7.5
CVE-2015-7888

Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or c…

No fix yet
Fix from $1,950 2017-06-07
Syncthru 6 CRITICAL 9.8
CVE-2015-5473EPSS 13%

Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified parame…

Mitigation only
Fix from $2,300 2017-06-01
Samsung Mobile HIGH 7.5
CVE-2017-7978

Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log …

Mitigation only
Fix from $1,950 2017-04-19
Galaxy S6 Firmware CRITICAL 9.8
CVE-2016-2566

Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices has SQL injection, aka SVE-2015-5081.

Mitigation only
Fix from $2,300 2017-04-13
Galaxy S6 Firmware MEDIUM 6.8
CVE-2016-4030

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I919…

No fix yet
Fix from $1,600 2017-04-13
Galaxy S6 Firmware MEDIUM 6.8
CVE-2016-4031

Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I919…

No fix yet
Fix from $1,600 2017-04-13
Galaxy S6 Firmware MEDIUM 5.5
CVE-2016-2036

The getURL function in drivers/secfilter/urlparser.c in secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G…

No fix yet
Fix from $1,600 2017-04-13
Galaxy S6 HIGH 8.8
CVE-2015-7893EPSS 7%

SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.

No fix yet
Fix from $1,950 2017-04-11
Galaxy App HIGH 8.0
CVE-2015-0863

GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obta…

Mitigation only
Fix from $1,950 2017-03-27
Galaxy App HIGH 8.0
CVE-2015-0864

Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information a…

Mitigation only
Fix from $1,950 2017-03-27
Nt14u Firmware CRITICAL 9.8
CVE-2015-5729

The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, whi…

No fix yet
Fix from $2,300 2017-03-23
Samsung Mobile HIGH 7.5
CVE-2016-4547

Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to …

Mitigation only
Fix from $1,950 2017-02-13
Samsung Mobile MEDIUM 5.5
CVE-2016-4546

Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a s…

Mitigation only
Fix from $1,600 2017-02-13