Vulnerabilities (CVE)

Filtered by vendor Samsung Subscribe
Total 1089 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-4763 1 Samsung 4 Galaxy S3, Galaxy S3 Firmware, Galaxy S4 and 1 more 2024-11-21 2.1 LOW 4.6 MEDIUM
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.
CVE-2013-3964 1 Samsung 2 Shr-5082, Shr-5162 2024-11-21 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Samsung SHR-5162, SHR-5082, and possibly other models, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CVE-2013-3586 1 Samsung 2 Dvr, Smart Viewer 2024-11-21 7.6 HIGH N/A
Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.
CVE-2013-3585 1 Samsung 2 Dvr, Smart Viewer 2024-11-21 5.0 MEDIUM N/A
Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page.
CVE-2012-6429 1 Samsung 1 Kies 2024-11-21 10.0 HIGH N/A
Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7 allows remote attackers to execute arbitrary code via a long string to the password argument.
CVE-2012-6422 2 Meizu, Samsung 3 Mx, Galaxy Note 2, Galaxy S2 2024-11-21 9.3 HIGH N/A
The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memory and gain privileges via a crafted application, as demonstrated by ExynosAbuse.
CVE-2012-6337 1 Samsung 4 Galaxy Note 2, Galaxy S, Galaxy S2 and 1 more 2024-11-21 3.3 LOW N/A
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices shows the activation of remote tracking, which might allow physically proximate attackers to defeat a product-recovery effort by tampering with this feature or its location data.
CVE-2012-6334 1 Samsung 4 Galaxy Note 2, Galaxy S, Galaxy S2 and 1 more 2024-11-21 2.9 LOW N/A
The Track My Mobile feature in the SamsungDive subsystem for Android on Samsung Galaxy devices does not properly implement Location APIs, which allows physically proximate attackers to provide arbitrary location data via a "commonly available simple GPS location spoofer."
CVE-2012-5859 1 Samsung 1 Kies Air 2024-11-21 5.0 MEDIUM N/A
Samsung Kies Air 2.1.207051 and 2.1.210161 allows remote attackers to cause a denial of service (crash) via a crafted request to www/apps/KiesAir/jws/ssd.php.
CVE-2012-5858 1 Samsung 1 Kies Air 2024-11-21 4.3 MEDIUM N/A
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-middle attackers to read arbitrary phone contents by spoofing or controlling the IP address.
CVE-2012-4964 1 Samsung 1 Printer Firmware 2024-11-21 7.5 HIGH N/A
The Samsung printer firmware before 20121031 has a hardcoded read-write SNMP community, which makes it easier for remote attackers to obtain administrative access via an SNMP request.
CVE-2012-4335 1 Samsung 1 Net-i Viewer 2024-11-21 7.8 HIGH N/A
Samsung NET-i viewer 1.37.120316 allows remote attackers to cause a denial of service (infinite loop) via a negative size value in a TCP request to (1) NiwMasterService or (2) NiwStorageService. NOTE: some of these details are obtained from third party information.
CVE-2012-4334 1 Samsung 1 Net-i Viewer 2024-11-21 10.0 HIGH N/A
The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i viewer 1.37.120316 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.
CVE-2012-4333 1 Samsung 1 Net-i Viewer 2024-11-21 10.0 HIGH N/A
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow remote attackers to execute arbitrary code via a long string in the fname parameter. NOTE: some of these details are obtained from third party information.
CVE-2012-4330 1 Samsung 2 D6000, D6000 Firmware 2024-11-21 7.8 HIGH N/A
The Samsung D6000 TV and possibly other products allows remote attackers to cause a denial of service (crash) via a long string in certain fields, as demonstrated by the MAC address field, possibly a buffer overflow.
CVE-2012-4329 1 Samsung 2 D6000, D6000 Firmware 2024-11-21 7.8 HIGH N/A
The Samsung D6000 TV and possibly other products allow remote attackers to cause a denial of service (continuous restart) via a crafted controller name.
CVE-2012-4250 1 Samsung 1 Net-i Viewer 2024-11-21 9.3 HIGH N/A
Stack-based buffer overflow in the RequestScreenOptimization function in the XProcessControl.ocx ActiveX control in msls31.dll in Samsung NET-i viewer 1.37 allows remote attackers to execute arbitrary code via a long string in the first argument.
CVE-2012-4050 2 Google, Samsung 5 Chrome Os, Cr-48 Chromebook, Chromebox 3 and 2 more 2024-11-21 10.0 HIGH N/A
Multiple unspecified vulnerabilities in Google Chrome OS before 21.0.1180.50 on the Cr-48 and Samsung Series 5 and 5 550 Chromebook platforms, and the Samsung Chromebox Series 3, have unknown impact and attack vectors.
CVE-2012-3810 1 Samsung 1 Kies 2024-11-21 5.0 MEDIUM 7.5 HIGH
Samsung Kies before 2.5.0.12094_27_11 has registry modification.
CVE-2012-3809 1 Samsung 1 Kies 2024-11-21 5.0 MEDIUM 7.5 HIGH
Samsung Kies before 2.5.0.12094_27_11 has arbitrary directory modification.