Skip to main content

Vendor/product archive

samsung / samsung_mobile CVEs

Beta · best-effort

28 CVEs tagged to samsung / samsung_mobile6 Critical, 14 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2018-10751

Published May 29, 2018

A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an int…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9143

Published Mar 30, 2018

On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged process, aka SVE-2017-10991.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-9142

Published Mar 30, 2018

On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation of a package signature and pa…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9141

Published Mar 30, 2018

On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a crafted resolution, aka SVE-201…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9140

Published Mar 30, 2018

On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9139

Published Mar 30, 2018

On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privileged process via a large frame size, aka SVE-2017-11165.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-5210

Published Jan 4, 2018

On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-18020

Published Jan 4, 2018

On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check du…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7896

Published Aug 24, 2017

LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2015-7891

Published Aug 2, 2017

Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory erro…

CVSS 7.0 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-7978

Published Apr 19, 2017

Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5538

Published Mar 23, 2017

The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4547

Published Feb 13, 2017

Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4546

Published Feb 13, 2017

Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a service call.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6527

Published Jan 18, 2017

The SmartCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly g…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6526

Published Jan 18, 2017

The SpamCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (crash and reboot) or possibly ga…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5351

Published Jan 12, 2017

Samsung Note devices with KK(4.4), L(5.0/5.1), and M(6.0) software allow attackers to crash the system by creating an arbitrarily large number of active VR service threads. The Sa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5350

Published Jan 12, 2017

Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allow attackers to crash systemUI by leveraging incomplete exception handling. The Samsung ID is SVE-2016-7122.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5217

Published Jan 9, 2017

Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process i…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9967

Published Dec 16, 2016

Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9966

Published Dec 16, 2016

Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9965

Published Dec 16, 2016

Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 28 CVEsPage 1 of 2