Skip to main content

Vendor archive

samsung CVEs

Beta · best-effort

1,628 CVEs tagged to vendor samsung113 Critical, 438 High, 965 Medium, 112 Low, 0 Unrated.

CVE-2025-54439

Published Jul 23, 2025

Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54438

Published Jul 23, 2025

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics MagicINFO 9 Server allows Upload a Web Shell to a Web Server.Th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-21009

Published Jul 8, 2025

Out-of-bounds read in decoding malformed frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21008

Published Jul 8, 2025

Out-of-bounds read in decoding frame header in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21007

Published Jul 8, 2025

Out-of-bounds write in accessing uninitialized memory in libsavsvc.so prior to Android 15 allows local attackers to cause memory corruption.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21006

Published Jul 8, 2025

Out-of-bounds write in handling of macro blocks for MPEG4 codec in libsavsvc.so prior to Android 15 allows local attackers to write out-of-bounds memory.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-21005

Published Jul 8, 2025

Improper access control in isemtelephony prior to Android 15 allows local attackers to access sensitive information.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21004

Published Jul 8, 2025

Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.

CVSS 6.2 · Medium

CVE-2025-21003

Published Jul 8, 2025

Insecure storage of sensitive information in Emergency SOS prior to SMR Jul-2025 Release 1 allows local attackers to access sensitive information.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21002

Published Jul 8, 2025

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21001

Published Jul 8, 2025

Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-21000

Published Jul 8, 2025

Improper privilege management in Bluetooth prior to SMR Jul-2025 Release 1 allows local attackers to enable Bluetooth.

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20999

Published Jul 8, 2025

Improper authorization in accessing saved Wi-Fi password for Galaxy Tablet prior to SMR Jul-2025 Release 1 allows secondary users to access owner's saved Wi-Fi password.

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20998

Published Jul 8, 2025

Improper access control in SamsungAccount for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to access phone number.

CVSS 5.5 · Medium

CVE-2025-20997

Published Jul 8, 2025

Incorrect default permission in Framework for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to reset some configuration of Galaxy Watch.

CVSS 6.2 · Medium

CVE-2025-20983

Published Jul 8, 2025

Out-of-bounds write in checking auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-20982

Published Jul 8, 2025

Out-of-bounds write in setting auth secret in KnoxVault trustlet prior to SMR Jul-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53076

Published Jun 30, 2025

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53074

Published Jun 30, 2025

Out-of-bounds Read vulnerability in Samsung Open Source rLottie allows Overflow Buffers.This issue affects rLottie: V0.2.

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53075

Published Jun 30, 2025

Improper Input Validation vulnerability in Samsung Open Source rLottie allows Path Traversal.This issue affects rLottie: V0.2.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0634

Published Jun 30, 2025

Use After Free vulnerability in Samsung Open Source rLottie allows Remote Code Inclusion.This issue affects rLottie: V0.2.

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 276-300 of 1,628 CVEsPage 12 of 66