Samsung mobile
This hub aggregates every CVE we track for Samsung mobile, a product in the ics ot iot space. Use it to gauge the current risk picture and drill into individual advisories.
29
CVEs tracked
7
Critical
14
High
1
In CISA KEV
Severity distribution
HIGH14MEDIUM8CRITICAL7
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Samsung mobile.
- CVE-2019-16256Some Samsung devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or e...KEV9.8
- CVE-2018-10751A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in m...5.3
- CVE-2018-9141On Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software, Gallery allows remote attackers to execute arbitrary code via a BMP file with a crafted resolution, aka SVE-2017-11105.7.8
- CVE-2018-9143On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged process, aka SVE-2017-10991.9.8
- CVE-2018-9139On Samsung mobile devices with N(7.x) software, a buffer overflow in the vision service allows code execution in a privileged process via a large frame size, aka SVE-2017-11165.9.8
- CVE-2018-9142On Samsung mobile devices with N(7.x) software, attackers can install an arbitrary APK in the Secure Folder SD Card area because of faulty validation of a package signature and package name, aka SV...7.0
- CVE-2018-9140On Samsung mobile devices with M(6.0) software, the Email application allows XSS via an event attribute and arbitrary file loading via a src attribute, aka SVE-2017-10747.6.1
- CVE-2018-5210On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a brute-force attack...8.1
- CVE-2017-18020On Samsung mobile devices with L(5.x), M(6.x), and N(7.x) software and Exynos chipsets, attackers can execute arbitrary code in the bootloader because S Boot omits a size check during a copy of ram...8.4
- CVE-2015-7896LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memory corruption and SIGSEGV) via a crafted image file.6.5
- CVE-2015-7891Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory errors by leveraging d...7.0
- CVE-2015-7895Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).5.5
- CVE-2015-7898Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).5.5
- CVE-2017-7978Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot. The Samsung ID ...7.5
- CVE-2017-5538The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers to have unspecified...9.8
Product normalization is registry-driven with AI assist and human review. How it works