Filtered by vendor Samsung Subscriptions
Total 969 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2022-28793 1 Samsung 2 Galaxy S22, Galaxy S22 Firmware 2022-05-11 4.4 Medium
Given the TEE is compromised and controlled by the attacker, improper state maintenance in StrongBox allows attackers to change Android ROT during device boot cycle after compromising TEE. The patch is applied in Galaxy S22 to prevent change of Android ROT after first initialization at boot time.
CVE-2021-25495 1 Samsung 1 Notes 2022-04-26 7.8 High
A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.
CVE-2021-25492 1 Samsung 1 Notes 2022-04-26 7.1 High
Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.
CVE-2018-11689 2 Hanwha-security, Samsung 19 Hrd-1641, Hrd-1641 Firmware, Hrd-1642 and 16 more 2022-04-24 6.1 Medium
Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the /cgi-bin/webviewer_login_page data3 parameter. (The same Web Viewer codebase was transitioned from Samsung to Hanwha.)
CVE-2022-27839 1 Samsung 1 Internet 2022-04-21 4.0 Medium
Improper authentication vulnerability in SecretMode in Samsung Internet prior to version 16.2.1 allows attackers to access bookmark tab without proper credentials.
CVE-2022-28543 1 Samsung 1 Samsung Flow 2022-04-21 5.5 Medium
Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as Samsung Flow permission.
CVE-2022-28544 1 Samsung 1 Galaxy Store 2022-04-21 5.5 Medium
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.
CVE-2022-28542 1 Samsung 1 Galaxy Store 2022-04-21 5.5 Medium
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local attackers to access privileged content providers as Galaxy Store permission.
CVE-2022-27841 1 Samsung 1 Samsung Pass 2022-04-19 4.3 Medium
Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication
CVE-2022-27840 1 Samsung 1 Recovery 2022-04-19 4.4 Medium
Improper access control vulnerability in SamsungRecovery prior to version 8.1.43.0 allows local attckers to delete arbitrary files as SamsungRecovery permission.
CVE-2018-3927 1 Samsung 2 Sth-eth-250, Sth-eth-250 Firmware 2022-04-19 N/A
An exploitable information disclosure vulnerability exists in the crash handler of the hubCore binary of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. When hubCore crashes, Google Breakpad is used to record minidumps, which are sent over an insecure HTTPS connection to the backtrace.io service, leading to the exposure of sensitive data. An attacker can impersonate the remote backtrace.io server in order to trigger this vulnerability.
CVE-2018-3925 1 Samsung 2 Sth-eth-250, Sth-eth-250 Firmware 2022-04-19 N/A
An exploitable buffer overflow vulnerability exists in the remote video-host communication of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17. The video-core process insecurely parses the AWSELB cookie while communicating with remote video-host servers, leading to a buffer overflow on the heap. An attacker able to impersonate the remote HTTP servers could trigger this vulnerability.
CVE-2022-28779 1 Samsung 1 Android Usb Driver Windows Installer 2022-04-19 7.8 High
Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code.
CVE-2022-27843 1 Samsung 1 Kies 2022-04-19 7.8 High
DLL hijacking vulnerability in Kies prior to version 2.6.4.22014_2 allows attacker to execute abitrary code.
CVE-2022-27842 1 Samsung 1 Smart Switch Pc 2022-04-19 7.8 High
DLL hijacking vulnerability in Smart Switch PC prior to version 4.2.22022_4 allows attacker to execute abitrary code.
CVE-2022-28541 1 Samsung 1 Update 2022-04-19 7.8 High
Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute arbitrary code as Samsung Update permission.
CVE-2022-27834 2 Google, Samsung 4 Android, Exynos 2100, Exynos 980 and 1 more 2022-04-18 7.0 High
Use after free vulnerability in dsp_context_unload_graph function of DSP driver prior to SMR Apr-2022 Release 1 allows attackers to perform malicious actions.
CVE-2022-27833 2 Google, Samsung 4 Android, Exynos 2100, Exynos 980 and 1 more 2022-04-18 7.8 High
Improper input validation in DSP driver prior to SMR Apr-2022 Release 1 allows out-of-bounds write by integer overflow.
CVE-2022-25154 1 Samsung 2 T5, T5 Firmware 2022-04-13 7.3 High
A DLL hijacking vulnerability in Samsung portable SSD T5 PC software before 1.6.9 could allow a local attacker to escalate privileges. (An attacker must already have user privileges on Windows 7, 10, or 11 to exploit this vulnerability.)
CVE-2022-25819 2 Google, Samsung 2 Android, Exynos 2022-03-16 5.5 Medium
OOB read vulnerability in hdcp2 device node prior to SMR Mar-2022 Release 1 allow an attacker to view Kernel stack memory.