Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Total 1008 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25351 2 Google, Samsung 2 Android, Account 2022-09-23 2.1 LOW 2.4 LOW
Improper Access Control in EmailValidationView in Samsung Account prior to version 10.7.0.7 and 12.1.1.3 allows physically proximate attackers to log out user account on device without user password.
CVE-2021-25366 1 Samsung 1 Internet 2022-09-23 3.6 LOW 2.9 LOW
Improper access control in Samsung Internet prior to version 13.2.1.70 allows physically proximate attackers to bypass the secret mode's authentication.
CVE-2021-25378 1 Samsung 1 Smartthings 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.
CVE-2021-25446 1 Samsung 2 Smartthings, Smartthings Firmware 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause arbitrary webpage loading in webview.
CVE-2021-25447 1 Samsung 2 Smartthings, Smartthings Firmware 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control vulnerability in SmartThings prior to version 1.7.67.25 allows untrusted applications to cause local file inclusion in webview.
CVE-2021-25448 1 Samsung 1 Smart Touch Call 2022-09-23 5.0 MEDIUM 5.3 MEDIUM
Improper access control vulnerability in Smart Touch Call prior to version 1.0.0.5 allows arbitrary webpage loading in webview.
CVE-2022-36851 1 Samsung 1 Samsung Pass 2022-09-21 N/A 4.6 MEDIUM
Improper access control vulnerability in Samsung pass prior to version 4.0.03.1 allow physical attackers to access data of Samsung pass on a certain state of an unlocked device.
CVE-2022-36865 2 Google, Samsung 2 Android, Group Sharing 2022-09-21 N/A 3.3 LOW
Improper access control in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to access device information.
CVE-2022-36864 1 Samsung 1 Samsung Email 2022-09-21 N/A 7.8 HIGH
Improper access control and intent redirection in Samsung Email prior to 6.1.70.20 allows attacker to access specific formatted file and execute privileged behavior.
CVE-2022-36866 2 Google, Samsung 2 Android, Group Sharing 2022-09-21 N/A 3.3 LOW
Improper access control vulnerability in Broadcaster in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
CVE-2022-36873 1 Samsung 1 Galaxy Watch Plugin 2022-09-21 N/A 6.5 MEDIUM
Improper restriction of broadcasting Intent in GalaxyStoreBridgePageLinker of?Waterplugin prior to version 2.2.11.22081151 leaks MAC address of the connected Bluetooth device.
CVE-2022-36874 1 Samsung 1 Galaxy Watch Plugin 2022-09-21 N/A 6.2 MEDIUM
Improper Handling of Insufficient Permissions or Privileges vulnerability in Waterplugin prior to 2.2.11.22040751 allows attacker to access device IMEI and Serial number.
CVE-2022-36877 1 Samsung 1 Samsung Members 2022-09-21 N/A 3.3 LOW
Exposure of Sensitive Information in FaqSymptomCardViewModel in Samsung Members prior to versions 4.3.00.11 in Global and 14.0.02.4 in China allows local attackers to access device identification via log.
CVE-2022-36878 1 Samsung 1 Find My Mobile 2022-09-21 N/A 3.3 LOW
Exposure of Sensitive Information in Find My Mobile prior to version 7.2.25.14 allows local attacker to access IMEI via log.
CVE-2022-39844 1 Samsung 1 Smart Switch Pc 2022-09-21 N/A 7.1 HIGH
Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3.22083 allows local attackers to delete arbitrary directory using directory junction.
CVE-2022-39845 1 Samsung 1 Kies 2022-09-21 N/A 7.1 HIGH
Improper validation of integrity check vulnerability in Samsung Kies prior to version 2.6.4.22074 allows local attackers to delete arbitrary directory using directory junction.
CVE-2022-39846 1 Samsung 1 Smart Switch Pc 2022-09-21 N/A 7.8 HIGH
DLL hijacking vulnerability in Smart Switch PC prior to version 4.3.22083_3 allows attacker to execute arbitrary code.
CVE-2022-40759 1 Samsung 1 Mtower 2022-09-21 N/A 7.5 HIGH
A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACCompareFinal with a NULL pointer for the parameter operation.
CVE-2022-40758 1 Samsung 1 Mtower 2022-09-21 N/A 7.5 HIGH
A Buffer Access with Incorrect Length Value vulnerablity in the TEE_CipherUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_CipherUpdate with an excessive size value of srcLen.
CVE-2022-40757 1 Samsung 1 Mtower 2022-09-21 N/A 7.5 HIGH
A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACComputeFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACComputeFinal with an excessive size value of messageLen.