Vulnerability index

Browse CVEs

1,202 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2018-3867 An exploitable stack-based buffer overflow vulnerability exists in the samsungWifiScan callback notification of video-core's HTTP server of Samsung S… Sth Eth 250 Firmware No fix yet Fix from $2,3002018-08-23 CRITICAL 9.9 CVE-2018-3878 Multiple exploitable buffer overflow vulnerabilities exist in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-… Sth Eth 250 Firmware No fix yet Fix from $2,3002018-08-23 HIGH 8.8 CVE-2018-3879 An exploitable JSON injection vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devi… Sth Eth 250 Firmware No fix yet Fix from $1,9502018-08-23 HIGH 8.8 CVE-2018-14908 Samsung Syncthru Web Service V4.05.61 is vulnerable to CSRF on every request, as demonstrated by sws.application/printinformation/printReportSetupVie… Syncthru Web Service No fix yet Fix from $1,9502018-08-03 MEDIUM 6.1 CVE-2018-14904 Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as demonstrated by ruiFw_pid. Syncthru Web Service No fix yet Fix from $1,6002018-08-03 MEDIUM 6.1 CVE-2018-11689 Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page dat… Smartviewer after 1.16 Fix from $1,6002018-06-14 MEDIUM 5.3 CVE-2018-10751EPSS 9% A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml … Samsung Mobile No fix yet Fix from $1,6002018-05-29 CRITICAL 9.8 CVE-2018-9139 On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privileged process via a large fra… Samsung Mobile Mitigation only Fix from $2,3002018-03-30 CRITICAL 9.8 CVE-2018-9143 On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged pr… Samsung Mobile Mitigation only Fix from $2,3002018-03-30 HIGH 7.8 CVE-2018-9141 On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a c… Samsung Mobile Mitigation only Fix from $1,9502018-03-30 HIGH 7.0 CVE-2018-9142 On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation… Samsung Mobile Mitigation only Fix from $1,9502018-03-30 MEDIUM 6.1 CVE-2018-9140 On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribut… Samsung Mobile Mitigation only Fix from $1,6002018-03-30 MEDIUM 5.9 CVE-2018-6019 Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption… Display Solutions after 3.01 Fix from $1,6002018-03-06 MEDIUM 5.9 CVE-2017-10963 In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker c… Knox Enterprise Mobility Management Mitigation only Fix from $1,6002018-02-20 HIGH 8.4 CVE-2017-18020 On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader becaus… Samsung Mobile Mitigation only Fix from $1,9502018-01-04 HIGH 8.1 CVE-2018-5210 On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code exe… Samsung Mobile Mitigation only Fix from $1,9502018-01-04 MEDIUM 6.1 CVE-2017-17859 Samsung Internet Browser 6.2.01.12 allows remote attackers to bypass the Same Origin Policy, and conduct UXSS attacks to obtain sensitive information… Internet Browser Mitigation only Fix from $1,6002017-12-27 HIGH 7.5 CVE-2017-17692EPSS 79% Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript co… Internet Browser No fix yet Fix from $1,9502017-12-21 HIGH 8.1 CVE-2017-14262 On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, … Srn 1670d Firmware Mitigation only Fix from $1,9502017-09-11 CRITICAL 9.8 CVE-2015-1801 The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to cause a denial of service (memory cor… Galaxy S4 Firmware Mitigation only Fix from $2,3002017-08-24 HIGH 7.5 CVE-2015-1800 The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive informat… Galaxy S4 Firmware No fix yet Fix from $1,9502017-08-24 MEDIUM 6.5 CVE-2015-7896EPSS 7% LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via… Samsung Mobile No fix yet Fix from $1,6002017-08-24 HIGH 8.8 CVE-2015-7894EPSS 9% The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allows remote attackers to cause a… Galaxy S6 Edge Firmware No fix yet Fix from $1,9502017-08-09 HIGH 7.0 CVE-2015-7891 Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows loca… Samsung Mobile No fix yet Fix from $1,9502017-08-02 MEDIUM 5.5 CVE-2015-7895 Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). Samsung Mobile No fix yet Fix from $1,6002017-06-27 MEDIUM 5.5 CVE-2015-7898 Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). Samsung Mobile No fix yet Fix from $1,6002017-06-27 HIGH 8.8 CVE-2017-3218 Samsung Magician 5.0 fails to validate TLS certificates for HTTPS software update traffic. Prior to version 5.0, Samsung Magician uses HTTP for softw… Magician Mitigation only Fix from $1,9502017-06-21 HIGH 7.5 CVE-2015-7888 Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or c… Galaxy S6 Edge Firmware No fix yet Fix from $1,9502017-06-07 CRITICAL 9.8 CVE-2015-5473EPSS 13% Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified parame… Syncthru 6 Mitigation only Fix from $2,3002017-06-01 HIGH 7.5 CVE-2017-7978 Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log … Samsung Mobile Mitigation only Fix from $1,9502017-04-19