Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Magician MEDIUM 5.5
CVE-2024-23769

Improper privilege control for the named pipe in Samsung Magician PC Software 8.0.0 (for Windows) allows a local attacker to read privileged data.

Mitigation only
Fix from $1,600 2024-02-07
Galaxy Store MEDIUM 5.5
CVE-2024-20823

Implicit intent hijacking vulnerability in SamsungAccount of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive inform…

Fix: 4.5.63.6+
Fix from $1,600 2024-02-06
Galaxy Store MEDIUM 5.5
CVE-2024-20824

Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive informati…

Fix: 4.5.63.6+
Fix from $1,600 2024-02-06
Galaxy Store MEDIUM 5.5
CVE-2024-20825

Implicit intent hijacking vulnerability in IAP of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via i…

Fix: 4.5.63.6+
Fix from $1,600 2024-02-06
Uphelper Library MEDIUM 5.5
CVE-2024-20826

Implicit intent hijacking vulnerability in UPHelper library prior to version 4.0.0 allows local attackers to access sensitive information via implici…

Fix: 4.0.0+
Fix from $1,600 2024-02-06
Android HIGH 7.8
CVE-2024-20817

Out-of-bounds Write vulnerabilities in svc1td_vld_slh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overfl…

Mitigation only
Fix from $1,950 2024-02-06
Android HIGH 7.8
CVE-2024-20818

Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overfl…

Mitigation only
Fix from $1,950 2024-02-06
Android HIGH 7.8
CVE-2024-20819

Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer ove…

Mitigation only
Fix from $1,950 2024-02-06
Android HIGH 7.1
CVE-2024-20820

Improper input validation in bootloader prior to SMR Feb-2024 Release 1 allows local privileged attackers to cause an Out-Of-Bounds read.

Mitigation only
Fix from $1,950 2024-02-06
Galaxy Store MEDIUM 5.5
CVE-2024-20822

Implicit intent hijacking vulnerability in AccountActivity of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive infor…

Fix: 4.5.63.6+
Fix from $1,600 2024-02-06
Android HIGH 7.8
CVE-2024-20812

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

Mitigation only
Fix from $1,950 2024-02-06
Android HIGH 7.8
CVE-2024-20813

Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

Mitigation only
Fix from $1,950 2024-02-06
Android MEDIUM 6.5
CVE-2024-20815

Improper authentication vulnerability in onCharacteristicReadRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers connec…

Mitigation only
Fix from $1,600 2024-02-06
Android MEDIUM 6.5
CVE-2024-20816

Improper authentication vulnerability in onCharacteristicWriteRequest in Auto Hotspot prior to SMR Feb-2024 Release 1 allows adjacent attackers conne…

Mitigation only
Fix from $1,600 2024-02-06
Android MEDIUM 5.5
CVE-2024-20814

Out-of-bounds Read in padmd_vld_ac_prog_refine of libpadm.so prior to SMR Feb-2024 Release 1 allows local attackers access unauthorized information.

Mitigation only
Fix from $1,600 2024-02-06
Nearby Device Scanning MEDIUM 5.5
CVE-2024-20808

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

Fix: 11.1.14.7+
Fix from $1,600 2024-01-04
Nearby Device Scanning MEDIUM 5.5
CVE-2024-20809

Improper access control vulnerability in Nearby device scanning prior version 11.1.14.7 allows local attacker to access data.

Fix: 11.1.14.7+
Fix from $1,600 2024-01-04
Android MEDIUM 6.5
CVE-2024-20803

Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing proce…

Mitigation only
Fix from $1,600 2024-01-04
Dex MEDIUM 5.5
CVE-2024-20802

Improper access control vulnerability in Samsung DeX prior to SMR Jan-2024 Release 1 allows owner to access other users' notification in a multi-…

Mitigation only
Fix from $1,600 2024-01-04
Android MEDIUM 5.5
CVE-2024-20804

Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in A…

Fix: 14.5.00.21+
Fix from $1,600 2024-01-04
Android MEDIUM 5.5
CVE-2024-20805

Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Andr…

Fix: 14.5.00.21+
Fix from $1,600 2024-01-04
Android MEDIUM 5.5
CVE-2024-20806

Improper access control in Notification service prior to SMR Jan-2024 Release 1 allows local attacker to access notification data.

Mitigation only
Fix from $1,600 2024-01-04
Escargot CRITICAL 9.8
CVE-2023-41268

Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: fr…

Patch available
Fix from $2,300 2023-12-06
Galaxy Store CRITICAL 9.8
CVE-2023-42580

Improper URL validation from MCSLaunch deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to install APK f…

Fix: 4.5.64.4+
Fix from $2,300 2023-12-05
Galaxy Store HIGH 7.5
CVE-2023-42581

Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4 allows attackers to execute JavaScript API to access data.

Fix: 4.5.64.4+
Fix from $1,950 2023-12-05
Gamehomecn HIGH 7.8
CVE-2023-42574

Improper access control vulnerablility in GameHomeCN prior to version 4.2.60.2 allows local attackers to launch arbitrary activity in GameHomeCN.

Fix: 4.2.60.2+
Fix from $1,950 2023-12-05
Cloud HIGH 7.5
CVE-2023-42578

Improper handling of insufficient permissions or privileges vulnerability in Samsung Data Store prior to version 5.2.00.7 allows remote attackers to …

Fix: after 5.2.00.7
Fix from $1,950 2023-12-05
Pass MEDIUM 6.8
CVE-2023-42575

Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid fl…

Fix: 4.3.00.17+
Fix from $1,600 2023-12-05
Pass MEDIUM 6.8
CVE-2023-42576

Improper Authentication vulnerability in Samsung Pass prior to version 4.3.00.17 allows physical attackers to bypass authentication due to invalid ex…

Fix: 4.3.00.17+
Fix from $1,600 2023-12-05
Samsung Keyboard MEDIUM 5.3
CVE-2023-42579

Improper usage of insecure protocol (i.e. HTTP) in SogouSDK of Chinese Samsung Keyboard prior to versions 5.3.70.1 in Android 11, 5.4.60.49, 5.4.85.5…

Fix: 5.3.70.1 / 5.4.60.49+
Fix from $1,600 2023-12-05