CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “samsung”

516 vulnerabilities found for “samsung”

Page 1 of 26

CVE-2023-42543
MEDIUM6.2

Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege.

samsung / bixby_voice
Local
Published Nov 7, 2023
Page 1 of 26
CVE-2021-25463
MEDIUM4.0

Improper access control vulnerability in PENUP prior to version 3.8.00.18 allows arbitrary webpage loading in webview.

samsung / penup
Local
Published Sep 9, 2021
CVE-2021-25398
LOW3.3

Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access contacts.

samsung / bixby_voice
Local
Published Jun 11, 2021
CVE-2021-25424
HIGH8.8

Improper authentication vulnerability in Tizen bluetooth-frwk prior to Firmware update JUN-2021 Release allows bluetooth attacker to take over the user's bluetooth device without user awareness.

samsung / galaxy_watch_active_2_firmware+8
Adjacent
Published Jun 11, 2021
CVE-2021-3438
HIGH7.8

A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege.

hp / color_laser_150_4zb94a+381
Local
Published May 20, 2021
CVE-2021-25352
MEDIUM5.5

Using PendingIntent with implicit intent in Bixby Voice prior to version 3.0.52.14 allows attackers to execute privileged action by hijacking and modifying the intent.

samsung / bixby_voice
Local
Published Mar 25, 2021
CVE-2018-20135
HIGH8.1

Samsung Galaxy Apps before 4.4.01.7 allows modification of the hostname used for load balancing on installations of applications through a man-in-the-middle attack. An attacker may trick Galaxy Apps into using an arbitrary hostname for which the attacker can provide a valid SSL certificate, and emulate the API of the app store to modify existing apps at installation time. The specific flaw involves an HTTP method to obtain the load-balanced hostname that enforces SSL only after obtaining a hostname from the load balancer, and a missing app signature validation in the application XML. An attacker can exploit this vulnerability to achieve Remote Code Execution on the device. The Samsung ID is SVE-2018-12071.

samsung / galaxy_apps
Network
Published Jun 7, 2019
CVE-2018-12037
MEDIUM4.0

An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk Encryption Key allows attackers with privileged access to SSD firmware full access to encrypted data.

samsung / 840_evo_firmware+6
Physical
Published Nov 20, 2018
CVE-2018-10500
HIGH7.0

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of push messages. The issue lies in the ability to start an activity with controlled arguments. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the application. Was ZDI-CAN-5331.

samsung / galaxy_apps
Local
Published Sep 24, 2018
CVE-2018-14318
HIGH8.8

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S8 G950FXXU1AQL5. User interaction is required to exploit this vulnerability in that the target must have their cellular radios enabled. The specific flaw exists within the handling of IPCP headers. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, stack-based buffer. An attacker can leverage this vulnerability to execute code under the context of the baseband processor. Was ZDI-CAN-5368.

samsung / galaxy_s8_firmware
Network
Published Sep 24, 2018
CVE-2018-10499
HIGH7.0

This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy Apps Fixed in version 6.4.0.15. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of URLs. The issue lies in the lack of proper validation of user-supplied data, which can allow arbitrary JavaScript to execute. An attacker can leverage this vulnerability to install applications under the context of the current user. Was ZDI-CAN-5330.

samsung / galaxy_apps
Local
Published Sep 24, 2018
CVE-2018-10502
HIGH7.8

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Samsung Galaxy Apps Fixed in version 4.2.18.2. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of a staging mode. The issue lies in the ability to change the configuration based on the presence of a file in an user-controlled location. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from the application. Was ZDI-CAN-5359.

samsung / galaxy_apps
Local
Published Sep 24, 2018
CVE-2018-10751
MEDIUM5.3

A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.

samsung / samsung_mobile+4
Network
Published May 29, 2018
CVE-2018-9141
HIGH7.8

On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a crafted resolution, aka SVE-2017-11105.

samsung / samsung_mobile+6
Local
Published Mar 30, 2018
CVE-2018-9139
CRITICAL9.8

On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privileged process via a large frame size, aka SVE-2017-11165.

samsung / samsung_mobile+3
Network
Published Mar 30, 2018
CVE-2018-9140
MEDIUM6.1

On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.

samsung / samsung_mobile
Network
Published Mar 30, 2018
CVE-2018-9142
HIGH7.0

On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation of a package signature and package name, aka SVE-2017-10932.

samsung / samsung_mobile+3
Local
Published Mar 30, 2018
CVE-2018-9143
CRITICAL9.8

On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged process, aka SVE-2017-10991.

samsung / samsung_mobile+4
Network
Published Mar 30, 2018
CVE-2017-18020
HIGH8.4

On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ramfs data to memory. The Samsung ID is SVE-2017-10598.

samsung / samsung_mobile+8
Local
Published Jan 4, 2018
CVE-2018-5210
HIGH8.1

On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a brute-force attack to discover unlock information (PIN, password, or pattern). The Samsung ID is SVE-2017-10733.

samsung / samsung_mobile+3
Network
Published Jan 4, 2018