Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Total 1399 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-21068 1 Samsung 1 Notes 2025-10-16 N/A 4.0 MEDIUM
Out-of-bounds read in the reading of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
CVE-2025-21069 1 Samsung 1 Notes 2025-10-16 N/A 4.0 MEDIUM
Out-of-bounds read in the parsing of image data in Samsung Notes prior to version 4.4.30.63 allows local attackers to access out-of-bounds memory.
CVE-2025-21070 1 Samsung 1 Notes 2025-10-16 N/A 4.0 MEDIUM
Out-of-bounds write in the SPI decoder in Samsung Notes prior to version 4.4.30.63 allows local attackers to write out-of-bounds memory.
CVE-2024-20854 2 Google, Samsung 2 Android, Camera 2025-10-10 N/A 5.9 MEDIUM
Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data.
CVE-2025-20926 2 Google, Samsung 2 Android, Myfiles 2025-10-03 N/A 5.5 MEDIUM
Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local attackers to access files with My Files' privilege.
CVE-2023-21481 1 Samsung 1 Account 2025-10-01 N/A 5.4 MEDIUM
Improper URL input validation vulnerability in Samsung Account application prior to version 14.1.0.0 allows remote attackers to get sensitive information.
CVE-2023-21482 2 Google, Samsung 2 Android, Camera 2025-10-01 N/A 6.1 MEDIUM
Missing authorization vulnerability in Camera prior to versions 11.1.02.18 in Android 11, 12.1.03.8 in Android 12 and 13.1.01.4 in Android 13 allows physical attackers to install package through Galaxy store before completion of Setup wizard.
CVE-2025-21035 2 Google, Samsung 2 Android, Calendar 2025-09-29 N/A 4.6 MEDIUM
Improper access control in Samsung Calendar prior to version 12.5.06.5 in Android 14 and 12.6.01.12 in Android 15 allows physical attackers to access data across multiple user profiles.
CVE-2024-49421 2 Google, Samsung 2 Android, Quick Share 2025-09-24 N/A 4.3 MEDIUM
Path traversal in Quick Share Agent prior to version 3.5.14.47 in Android 12, 3.5.19.41 in Android 13, and 3.5.19.42 in Android 14 allows adjacent attackers to write file in arbitrary location.
CVE-2023-21468 1 Samsung 1 Android 2025-09-19 N/A 5.9 MEDIUM
Improper access control vulnerability in Telephony prior to SMR Apr-2023 Release 1 allows attackers to access files with escalated permission.
CVE-2023-21469 1 Samsung 1 Android 2025-09-19 N/A 4.0 MEDIUM
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.GEOFENCE action.
CVE-2023-21470 1 Samsung 1 Android 2025-09-19 N/A 4.0 MEDIUM
Improper access control vulnerability in SLocation prior to SMR Apr-2022 Release 1 allows local attackers to get device location information using com.samsung.android.wifi.NETWORK_LOCATION action.
CVE-2023-21474 1 Samsung 1 Android 2025-09-19 N/A 6.3 MEDIUM
Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.
CVE-2023-21478 1 Samsung 1 Android 2025-09-19 N/A 6.0 MEDIUM
Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.
CVE-2023-21480 1 Samsung 1 Android 2025-09-19 N/A 8.5 HIGH
Improper input validation vulnerability in CertByte prior to SMR Apr-2023 Release 1 allows local attackers to launch privileged activities.
CVE-2025-21041 1 Samsung 1 Android 2025-09-19 N/A 6.2 MEDIUM
Insecure Storage of Sensitive Information in Secure Folder prior to Android 16 allows local attackers to access sensitive information.
CVE-2025-21042 1 Samsung 1 Android 2025-09-19 N/A 8.8 HIGH
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
CVE-2025-21034 1 Samsung 1 Android 2025-09-11 N/A 4.0 MEDIUM
Out-of-bounds write in libsavsvc.so prior to SMR Sep-2025 Release 1 allows local attackers to potentially execute arbitrary code.
CVE-2025-21033 1 Samsung 1 Android 2025-09-11 N/A 4.0 MEDIUM
Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.
CVE-2025-21032 1 Samsung 1 Android 2025-09-11 N/A 5.9 MEDIUM
Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.