Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Total 1631 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-25401 1 Samsung 1 Health 2026-06-17 4.6 MEDIUM 7.8 HIGH
Intent redirection vulnerability in Samsung Health prior to version 6.16 allows attacker to execute privileged action.
CVE-2021-25400 1 Samsung 1 Internet 2026-06-17 4.6 MEDIUM 7.8 HIGH
Intent redirection vulnerability in Samsung Internet prior to version 14.0.1.20 allows attacker to execute privileged action.
CVE-2021-25399 1 Samsung 1 Smart Manager 2026-06-17 3.6 LOW 7.1 HIGH
Improper configuration in Smart Manager prior to version 11.0.05.0 allows attacker to access the file with system privilege.
CVE-2021-25398 1 Samsung 1 Bixby Voice 2026-06-17 2.1 LOW 3.3 LOW
Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access contacts.
CVE-2021-25396 2 Google, Samsung 5 Android, Exynos 2100, Exynos 980 and 2 more 2026-06-17 4.6 MEDIUM 6.7 MEDIUM
An improper input validation vulnerability in NPU firmware prior to SMR MAY-2021 Release 1 allows arbitrary memory write and code execution.
CVE-2021-25395 1 Samsung 1 Android 2026-06-17 4.4 MEDIUM 6.4 MEDIUM
A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
CVE-2021-25394 1 Samsung 1 Android 2026-06-17 4.4 MEDIUM 6.4 MEDIUM
A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
CVE-2021-25381 2 Google, Samsung 2 Android, Account 2026-06-17 4.6 MEDIUM 5.5 MEDIUM
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
CVE-2021-25380 1 Samsung 1 Bixby 2026-06-17 7.5 HIGH 5.8 MEDIUM
Improper handling of exceptional conditions in Bixby prior to version 3.0.53.02 allows attacker to execute the actions registered by the user.
CVE-2021-25379 1 Samsung 1 Gallery 2026-06-17 2.1 LOW 4.0 MEDIUM
Intent redirection vulnerability in Gallery prior to version 5.4.16.1 allows attacker to execute privileged action.
CVE-2021-25378 1 Samsung 1 Smartthings 2026-06-17 5.0 MEDIUM 4.3 MEDIUM
Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of service.
CVE-2021-25377 2 Google, Samsung 2 Android, Experience Service 2026-06-17 4.6 MEDIUM 3.3 LOW
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.
CVE-2021-25376 1 Samsung 1 Email 2026-06-17 5.0 MEDIUM 3.1 LOW
An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.
CVE-2021-25375 1 Samsung 1 Email 2026-06-17 4.3 MEDIUM 6.5 MEDIUM
Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment.
CVE-2021-25374 2 Google, Samsung 2 Android, Members 2026-06-17 5.0 MEDIUM 8.6 HIGH
An improper authorization vulnerability in Samsung Members "samsungrewards" scheme for deeplink in versions 2.4.83.9 in Android O(8.1) and below, and 3.9.00.9 in Android P(9.0) and above allows remote attackers to access a user data related with Samsung Account.
CVE-2021-25373 2 Google, Samsung 2 Android, Customization Service 2026-06-17 4.6 MEDIUM 5.5 MEDIUM
Using unsafe PendingIntent in Customization Service prior to version 2.2.02.1 in Android O(8.x), 2.4.03.0 in Android P(9.0), 2.7.02.1 in Android Q(10.0) and 2.9.01.1 in Android R(11.0) allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
CVE-2021-25372 1 Samsung 4 Android, Exynos 2100, Exynos 980 and 1 more 2026-06-17 7.2 HIGH 6.1 MEDIUM
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
CVE-2021-25371 1 Samsung 4 Android, Exynos 2100, Exynos 980 and 1 more 2026-06-17 7.2 HIGH 6.1 MEDIUM
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
CVE-2021-25370 1 Samsung 1 Android 2026-06-17 4.9 MEDIUM 6.1 MEDIUM
An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory corruption leading to kernel panic.
CVE-2021-25369 1 Samsung 1 Android 2026-06-17 2.1 LOW 6.2 MEDIUM
An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel information to userspace.