Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sth Eth 250 Firmware CRITICAL 9.9
CVE-2018-3867

An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-core's HTTP server of Samsung S…

No fix yet
Fix from $2,300 2018-08-23
Sth Eth 250 Firmware CRITICAL 9.9
CVE-2018-3878

Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-…

No fix yet
Fix from $2,300 2018-08-23
Sth Eth 250 Firmware HIGH 8.8
CVE-2018-3879

An exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devi…

No fix yet
Fix from $1,950 2018-08-23
Syncthru Web Service HIGH 8.8
CVE-2018-14908

Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupVie…

No fix yet
Fix from $1,950 2018-08-03
Syncthru Web Service MEDIUM 6.1
CVE-2018-14904

Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as demonstrated by ruiFw_pid.

No fix yet
Fix from $1,600 2018-08-03
Smartviewer MEDIUM 6.1
CVE-2018-11689

Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page dat…

Fix: after 1.16
Fix from $1,600 2018-06-14
Samsung Mobile MEDIUM 5.3
CVE-2018-10751EPSS 9%

A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml …

No fix yet
Fix from $1,600 2018-05-29
Samsung Mobile CRITICAL 9.8
CVE-2018-9139

On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privileged process via a large fra…

Mitigation only
Fix from $2,300 2018-03-30
Samsung Mobile CRITICAL 9.8
CVE-2018-9143

On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged pr…

Mitigation only
Fix from $2,300 2018-03-30
Samsung Mobile HIGH 7.8
CVE-2018-9141

On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a c…

Mitigation only
Fix from $1,950 2018-03-30
Samsung Mobile HIGH 7.0
CVE-2018-9142

On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation…

Mitigation only
Fix from $1,950 2018-03-30
Samsung Mobile MEDIUM 6.1
CVE-2018-9140

On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribut…

Mitigation only
Fix from $1,600 2018-03-30
Display Solutions MEDIUM 5.9
CVE-2018-6019

Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption…

Fix: after 3.01
Fix from $1,600 2018-03-06
Knox Enterprise Mobility Management MEDIUM 5.9
CVE-2017-10963

In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker c…

Mitigation only
Fix from $1,600 2018-02-20
Samsung Mobile HIGH 8.4
CVE-2017-18020

On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader becaus…

Mitigation only
Fix from $1,950 2018-01-04
Samsung Mobile HIGH 8.1
CVE-2018-5210

On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code exe…

Mitigation only
Fix from $1,950 2018-01-04
Internet Browser MEDIUM 6.1
CVE-2017-17859

Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information…

Mitigation only
Fix from $1,600 2017-12-27
Internet Browser HIGH 7.5
CVE-2017-17692EPSS 79%

Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript co…

No fix yet
Fix from $1,950 2017-12-21
Srn 1670d Firmware HIGH 8.1
CVE-2017-14262

On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, …

Mitigation only
Fix from $1,950 2017-09-11
Galaxy S4 Firmware CRITICAL 9.8
CVE-2015-1801

The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory cor…

Mitigation only
Fix from $2,300 2017-08-24
Galaxy S4 Firmware HIGH 7.5
CVE-2015-1800

The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive informat…

No fix yet
Fix from $1,950 2017-08-24
Samsung Mobile MEDIUM 6.5
CVE-2015-7896EPSS 7%

LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via…

No fix yet
Fix from $1,600 2017-08-24
Galaxy S6 Edge Firmware HIGH 8.8
CVE-2015-7894EPSS 9%

The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a…

No fix yet
Fix from $1,950 2017-08-09
Samsung Mobile HIGH 7.0
CVE-2015-7891

Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows loca…

No fix yet
Fix from $1,950 2017-08-02
Samsung Mobile MEDIUM 5.5
CVE-2015-7895

Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

No fix yet
Fix from $1,600 2017-06-27
Samsung Mobile MEDIUM 5.5
CVE-2015-7898

Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

No fix yet
Fix from $1,600 2017-06-27
Magician HIGH 8.8
CVE-2017-3218

Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for softw…

Mitigation only
Fix from $1,950 2017-06-21
Galaxy S6 Edge Firmware HIGH 7.5
CVE-2015-7888

Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or c…

No fix yet
Fix from $1,950 2017-06-07
Syncthru 6 CRITICAL 9.8
CVE-2015-5473EPSS 13%

Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified parame…

Mitigation only
Fix from $2,300 2017-06-01
Samsung Mobile HIGH 7.5
CVE-2017-7978

Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log …

Mitigation only
Fix from $1,950 2017-04-19