Filtered by vendor Samsung
Subscribe
Total
1672 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-25204 | 1 Samsung | 1 Escargot | 2026-06-17 | N/A | 6.2 MEDIUM |
| Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows denial of service condition via process abort. This issue affects escarogt prior to commit hash 97e8115ab1110bc502b4b5e4a0c689a71520d335 | |||||
| CVE-2026-25202 | 1 Samsung | 1 Magicinfo 9 Server | 2026-06-17 | N/A | 9.8 CRITICAL |
| The database account and password are hardcoded, allowing login with the account to manipulate the database in MagicInfo9 Server.This issue affects MagicINFO 9 Server: less than 21.1090.1. | |||||
| CVE-2026-25201 | 1 Samsung | 1 Magicinfo 9 Server | 2026-06-17 | N/A | 8.8 HIGH |
| An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server. This issue affects MagicINFO 9 Server: less than 21.1090.1. | |||||
| CVE-2026-25200 | 1 Samsung | 1 Magicinfo 9 Server | 2026-06-17 | N/A | 9.8 CRITICAL |
| A vulnerability in MagicInfo9 Server allows authorized users to upload HTML files without authentication, leading to Stored XSS, which can result in account takeover This issue affects MagicINFO 9 Server: less than 21.1090.1. | |||||
| CVE-2026-21033 | 1 Samsung | 1 Assistant | 2026-06-17 | N/A | 7.1 HIGH |
| Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | |||||
| CVE-2026-21032 | 1 Samsung | 1 Assistant | 2026-06-17 | N/A | 7.1 HIGH |
| Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script. | |||||
| CVE-2026-21031 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability. | |||||
| CVE-2026-21030 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions. | |||||
| CVE-2026-21029 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations. | |||||
| CVE-2026-21028 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | |||||
| CVE-2026-21027 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 3.3 LOW |
| Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function. | |||||
| CVE-2026-21026 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information. | |||||
| CVE-2026-21025 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information. | |||||
| CVE-2026-21023 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application. | |||||
| CVE-2026-21022 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | |||||
| CVE-2026-21021 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.8 MEDIUM |
| Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity. | |||||
| CVE-2026-21020 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper export of android application components in OmaCP prior to SMR May-2026 Release 1 allows local attackers to trigger privileged functions. | |||||
| CVE-2026-21018 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.7 MEDIUM |
| Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code. | |||||
| CVE-2026-21017 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files. | |||||
| CVE-2026-21016 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | |||||
