Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Kies HIGH 7.8
CVE-2022-27843

DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.

Fix: 2.6.4.22014_2+
Fix from $1,950 2022-04-11
Update HIGH 7.8
CVE-2022-28541

Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Upda…

Fix: 3.0.77.0+
Fix from $1,950 2022-04-11
Galaxy Store HIGH 7.8
CVE-2022-28776

Improper access control vulnerability in Galaxy Store prior to version 4.5.36.4 allows attacker to install applications from Galaxy Store without use…

Fix: 4.5.36.4+
Fix from $1,950 2022-04-11
Android Usb Driver Windows Installer HIGH 7.8
CVE-2022-28779

Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to exe…

Fix: 1.7.50+
Fix from $1,950 2022-04-11
Galaxy Store MEDIUM 5.5
CVE-2022-28542

Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as G…

Fix: 4.5.40.5+
Fix from $1,600 2022-04-11
Samsung Flow MEDIUM 5.5
CVE-2022-28543

Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission.

Fix: 4.8.07.4+
Fix from $1,600 2022-04-11
Galaxy Store MEDIUM 5.5
CVE-2022-28544

Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file…

Fix: 4.5.40.5+
Fix from $1,600 2022-04-11
Accessibility HIGH 7.8
CVE-2022-27837

A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to …

Fix: 12.5.3.2 / 13.0.1.1+
Fix from $1,950 2022-04-11
T5 Firmware HIGH 7.3
CVE-2022-25154

A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escalate privileges. (An attacker m…

Fix: 1.6.9+
Fix from $1,950 2022-04-05
Video Player CRITICAL 9.8
CVE-2022-24927

Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permis…

Fix: 7.3.15.30+
Fix from $2,300 2022-02-11
Camera MEDIUM 5.5
CVE-2022-23998

Improper access control vulnerability in Camera prior to versions 11.1.02.16 in Android R(11), 10.5.03.77 in Android Q(10) and 9.0.6.68 in Android P(…

Fix: 9.0.6.68 / 10.5.03.77+
Fix from $1,600 2022-02-11
Smarttagplugin MEDIUM 5.4
CVE-2022-24926

Improper input validation vulnerability in SmartTagPlugin prior to version 1.2.15-6 allows privileged attackers to trigger a XSS on a victim's device…

Fix: 1.2.15-6+
Fix from $1,600 2022-02-11
Link Sharing MEDIUM 5.3
CVE-2022-24002

Improper Authorization vulnerability in Link Sharing prior to version 12.4.00.3 allows attackers to open protected activity via PreconditionActivity.

Fix: 12.4.00.3+
Fix from $1,600 2022-02-11
Bixby Vision MEDIUM 5.3
CVE-2022-24003

Exposure of Sensitive Information vulnerability in Bixby Vision prior to version 3.7.50.6 allows attackers to access internal data of Bixby Vision vi…

Fix: 3.7.50.6+
Fix from $1,600 2022-02-11
Livewallpaperservice MEDIUM 5.3
CVE-2022-24924

An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper perm…

Fix: 3.0.9.0+
Fix from $1,600 2022-02-11
Reminder MEDIUM 5.3
CVE-2022-23433

Improper access control vulnerability in Reminder prior to versions 12.3.01.3000 in Android S(12), 12.2.05.6000 in Android R(11) and 11.6.08.6000 in …

Fix: 11.6.08.6000 / 12.2.05.6000+
Fix from $1,600 2022-02-11
Internet MEDIUM 6.5
CVE-2022-22290

Incorrect download source UI in Downloads in Samsung Internet prior to 16.0.6.23 allows attackers to perform domain spoofing via a crafted HTML page.

Fix: 16.0.6.23+
Fix from $1,600 2022-01-14
Galaxy Store HIGH 7.5
CVE-2022-22288

Improper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.

Fix: 4.5.36.5+
Fix from $1,950 2022-01-10
S Assistant MEDIUM 5.3
CVE-2022-22289

Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.

Fix: 7.5+
Fix from $1,600 2022-01-10
Bixby Routines HIGH 7.1
CVE-2022-22286

A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows attackers t…

Fix: 2.6.30.5 / 3.1.21.8+
Fix from $1,950 2022-01-10
Reminder HIGH 7.1
CVE-2022-22285

A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attackers to…

Fix: 12.2.05.0 / 12.3.02.1000+
Fix from $1,950 2022-01-10
Internet MEDIUM 5.5
CVE-2022-22284

Improper authentication vulnerability in Samsung Internet prior to 16.0.2.19 allows attackers to bypass secret mode password authentication

Fix: 16.0.2.19+
Fix from $1,600 2022-01-10
Syncthru Web Service HIGH 7.5
CVE-2021-42913

The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading th…

Mitigation only
Fix from $1,950 2021-12-20
Pay MEDIUM 6.5
CVE-2021-25525

Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without …

Fix: 4.0.65+
Fix from $1,600 2021-12-08
Internet MEDIUM 6.1
CVE-2021-25520

Insecure caller check and input validation vulnerabilities in SearchKeyword deeplink logic prior to Samsung Internet 16.0.2 allows unstrusted applica…

Fix: 16.0.2+
Fix from $1,600 2021-12-08
Blockchain Wallet MEDIUM 5.5
CVE-2021-25526

Intent redirection vulnerability in Samsung Blockchain Wallet prior to version 1.3.02.8 allows attacker to execute privileged action.

Fix: 1.3.02.8+
Fix from $1,600 2021-12-08
Ddr4 Sdram Firmware HIGH 8.3
CVE-2021-42114

Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attack…

No fix yet
Fix from $1,950 2021-11-16
Samsung Flow HIGH 7.1
CVE-2021-25509

A missing input validation in Samsung Flow Windows application prior to Version 4.8.5.0 allows attackers to overwrite abtraty file in the Windows kno…

Fix: 4.8.5.0+
Fix from $1,950 2021-11-05
Smartthings CRITICAL 9.8
CVE-2021-25508

Improper privilege management vulnerability in API Key used in SmartThings prior to 1.7.73.22 allows an attacker to abuse the API key without limitat…

Fix: 1.7.73.22+
Fix from $2,300 2021-11-05
Samsung Pass HIGH 7.8
CVE-2021-25505

Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.

Fix: 3.0.02.4+
Fix from $1,950 2021-11-05