Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Galaxy Watch Plugin MEDIUM 5.5
CVE-2021-25420

Improper log management vulnerability in Galaxy Watch PlugIn prior to version 2.2.05.21033151 allows attacker with log permissions to leak Wi-Fi pass…

Fix: 2.2.05.21033151+
Fix from $1,600 2021-06-11
Galaxy Watch 3 Plugin MEDIUM 5.5
CVE-2021-25421

Improper log management vulnerability in Galaxy Watch3 PlugIn prior to version 2.2.09.21033151 allows attacker with log permissions to leak Wi-Fi pas…

Fix: 2.2.09.21033151+
Fix from $1,600 2021-06-11
Watch Active Plugin MEDIUM 5.5
CVE-2021-25422

Improper log management vulnerability in Watch Active PlugIn prior to version 2.2.07.21033151 allows attacker with log permissions to leak Wi-Fi pass…

Fix: 2.2.07.21033151+
Fix from $1,600 2021-06-11
Watch Active2 Plugin MEDIUM 5.5
CVE-2021-25423

Improper log management vulnerability in Watch Active2 PlugIn prior to 2.2.08.21033151 version allows attacker with log permissions to leak Wi-Fi pas…

Fix: 2.2.08.21033151+
Fix from $1,600 2021-06-11
Internet HIGH 7.8
CVE-2021-25400

Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.

Fix: 14.0.1.20+
Fix from $1,950 2021-06-11
Health HIGH 7.8
CVE-2021-25401

Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.

Fix: 6.16+
Fix from $1,950 2021-06-11
Smart Manager HIGH 7.1
CVE-2021-25399

Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.

Fix: 11.0.05.0+
Fix from $1,950 2021-06-11
Gear S MEDIUM 6.5
CVE-2021-25406

Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT device inf…

Fix: 2.2.05.20122441+
Fix from $1,600 2021-06-11
Android MEDIUM 6.4
CVE-2021-25395 KEV

A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is co…

Mitigation only
Fix from $1,600 2021-06-11
Notes MEDIUM 5.5
CVE-2021-25405

An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to access loc…

Fix: 4.2.04.27+
Fix from $1,600 2021-06-11
Android MEDIUM 6.4
CVE-2021-25394 KEV

A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privileg…

Mitigation only
Fix from $1,600 2021-06-11
Galaxy I9305 Firmware MEDIUM 6.5
CVE-2020-26144

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext A-MSDU frames as long…

Fix: 10.0.1-31 / 11.0.0-36+
Fix from $1,600 2021-05-11
Galaxy I9305 Firmware MEDIUM 6.5
CVE-2020-26145

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept second (or subsequent) broadcas…

Fix: 1.2+
Fix from $1,600 2021-05-11
Galaxy I9305 Firmware MEDIUM 5.3
CVE-2020-26146EPSS 6%

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive p…

Fix: 10.0.1-31 / 11.0.0-36+
Fix from $1,600 2021-05-11
Customization Service HIGH 7.8
CVE-2021-25373

Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10…

Fix: 2.2.02.1 / 2.4.03.0+
Fix from $1,950 2021-04-09
Experience Service HIGH 7.8
CVE-2021-25377

Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to …

Fix: after 10.8.0.4
Fix from $1,950 2021-04-09
Account HIGH 7.8
CVE-2021-25381

Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows loca…

Mitigation only
Fix from $1,950 2021-04-09
Members HIGH 7.5
CVE-2021-25374

An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and…

Fix: after 2.4.83.9
Fix from $1,950 2021-04-09
Bixby HIGH 7.3
CVE-2021-25380

Improper handling of exceptional conditions in Bixby prior to version 3.0.53.02 allows attacker to execute the actions registered by the user.

Fix: 3.0.53.02+
Fix from $1,950 2021-04-09
Email MEDIUM 6.5
CVE-2021-25375

Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when …

Fix: 6.1.14.0+
Fix from $1,600 2021-04-09
Email MEDIUM 5.3
CVE-2021-25376

An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotia…

Fix: 6.1.41.0+
Fix from $1,600 2021-04-09
Smartthings MEDIUM 5.3
CVE-2021-25378

Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.

Fix: 1.7.63.6+
Fix from $1,600 2021-04-09
Android MEDIUM 6.7
CVE-2021-25371 KEV

A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.

Mitigation only
Fix from $1,600 2021-03-26
Android MEDIUM 6.7
CVE-2021-25372 KEV

An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.

Mitigation only
Fix from $1,600 2021-03-26
Android MEDIUM 5.5
CVE-2021-25369 KEV

An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.

Mitigation only
Fix from $1,600 2021-03-26
Cloud HIGH 7.5
CVE-2021-25368

Hijacking vulnerability in Samsung Cloud prior to version 4.7.0.3 allows attackers to intercept when the provider is executed.

Fix: 4.7.0.3+
Fix from $1,950 2021-03-25
Notes MEDIUM 5.4
CVE-2021-25367

Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.

Fix: 4.2.00.22+
Fix from $1,600 2021-03-25
Slow Motion Editor HIGH 7.8
CVE-2021-25349

Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijackin…

Fix: 3.5.18.5+
Fix from $1,950 2021-03-25
Bixby Voice HIGH 7.8
CVE-2021-25352

Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and mod…

Fix: 3.0.52.14+
Fix from $1,950 2021-03-25
Notes HIGH 7.8
CVE-2021-25355

Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking th…

Fix: 4.2.00.22+
Fix from $1,950 2021-03-25