Filtered by vendor Samsung
Subscribe
Total
1631 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-20990 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 8.1 HIGH |
| Improper export of android application components in Secure Folder prior to SMR Mar-2026 Release 1 allows local attackers to launch arbitrary activity with Secure Folder privilege. | |||||
| CVE-2026-20989 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 2.4 LOW |
| Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font. | |||||
| CVE-2026-20988 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.0 MEDIUM |
| Improper verification of intent by broadcast receiver in Settings prior to SMR Mar-2026 Release 1 allows local attacker to launch arbitrary activity with Settings privilege. User interaction is required for triggering this vulnerability. | |||||
| CVE-2026-20986 | 1 Samsung | 1 Members | 2026-06-17 | N/A | 5.5 MEDIUM |
| Path traversal in Samsung Members prior to Chinese version 15.5.05.4 allows local attackers to overwrite data within Samsung Members. | |||||
| CVE-2026-20985 | 1 Samsung | 1 Members | 2026-06-17 | N/A | 4.3 MEDIUM |
| Improper input validation in Samsung Members prior to version 5.6.00.11 allows remote attackers to connect arbitrary URL and launch arbitrary activity with Samsung Members privilege. User interaction is required for triggering this vulnerability. | |||||
| CVE-2026-20983 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper export of android application components in Samsung Dialer prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Samsung Dialer privilege. | |||||
| CVE-2026-20982 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.0 MEDIUM |
| Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege. | |||||
| CVE-2026-20981 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.6 MEDIUM |
| Improper input validation in FacAtFunction prior to SMR Feb-2026 Release 1 allows privileged physical attacker to execute arbitrary command with system privilege. | |||||
| CVE-2026-20980 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.8 MEDIUM |
| Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands. | |||||
| CVE-2026-20979 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper privilege management in Settings prior to SMR Feb-2026 Release 1 allows local attackers to launch arbitrary activity with Settings privilege. | |||||
| CVE-2026-20978 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 6.1 MEDIUM |
| Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. | |||||
| CVE-2026-20977 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning. | |||||
| CVE-2026-20976 | 1 Samsung | 1 Galaxy Store | 2026-06-17 | N/A | 7.8 HIGH |
| Improper input validation in Galaxy Store prior to version 4.6.02 allows local attacker to execute arbitrary script. | |||||
| CVE-2026-20975 | 1 Samsung | 1 Cloud | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary path. | |||||
| CVE-2026-20974 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 4.6 MEDIUM |
| Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attackers to bypass Carrier Relock. | |||||
| CVE-2026-20973 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.3 MEDIUM |
| Out-of-bounds read in libimagecodec.quram.so prior to SMR Jan-2026 Release 1 allows remote attacker to access out-of-bounds memory. | |||||
| CVE-2026-20972 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 3.3 LOW |
| Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB. | |||||
| CVE-2026-20971 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Use After Free in PROCA driver prior to SMR Jan-2026 Release 1 allows local attackers to potentially execute arbitrary code. | |||||
| CVE-2026-20970 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 7.8 HIGH |
| Improper access control in SLocation prior to SMR Jan-2026 Release 1 allows local attackers to execute the privileged APIs. | |||||
| CVE-2026-20969 | 1 Samsung | 1 Android | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interaction is required for triggering this vulnerability. | |||||
