Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Samsung

First CVE: Jul 17, 2001Active for: 25 yearsTotal CVEs: 1,527
51.6
VTI Score
TOP TARGET

Samsung's vulnerability footprint spans a very broad portfolio of consumer electronics, mobile devices, and semiconductor components—including Android devices, custom Exynos processors and firmware—representing one of the largest and most widely deployed attack surfaces in the landscape. Vulnerabilities affecting the vendor skew toward moderate severity outcomes, with the exposure concentrating in Exynos processor firmware and Android implementations through weakness classes including out-of-bounds memory operations and improper input validation, reflecting the complexity of custom silicon and mobile platform integration. The recurrence of memory-safety issues and input-handling flaws across processor and firmware layers underscores the structural challenges of validating hardware-level and low-level software components at scale. Defenders should prioritize firmware updates and device patching across Samsung's mobile ecosystem, where supply-chain coordination and carrier delays often complicate timely remediation; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
1,527
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
1.0%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Samsung over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2001
25 years ago
Most Recent CVE
Jun 5, 2026
53 days ago

Products(1,666 total)

Top CVEs

Signals from CVEs in this vendor scope (1527 CVEs).

1,527 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-7399CRITICAL
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system au
Aug 12, 20249.898YESYES
CVE-2025-21042CRITICAL
Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code.
Sep 12, 20259.887YESNO
CVE-2025-4632CRITICAL
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system au
May 13, 20259.887YESYES
CVE-2017-17692HIGH
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child ta
Dec 21, 20177.583NOYES
CVE-2012-4333HIGH
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow
Aug 14, 201210.078NOYES
CVE-2025-21043CRITICAL
Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code.
Sep 12, 20259.875YESNO
CVE-2016-1010HIGH
Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176,
Mar 12, 20168.871YESNO
CVE-2021-25487HIGH
Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dere
Oct 6, 20217.863YESNO
CVE-2021-25372MEDIUM
An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
Mar 26, 20216.760YESNO
CVE-2021-25337HIGH
Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files.
Mar 4, 20217.160YESNO
View all 1,527 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,527 CVEs
11%
42%
38%
9%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local838 (54.9%)
Network475 (31.1%)
Unknown43 (2.8%)
Physical119 (7.8%)
Adjacent Network52 (3.4%)
Attack Complexity
Low1,426 (93.4%)
High58 (3.8%)
Unknown43 (2.8%)
User Interaction
None1,294 (84.7%)
Unknown43 (2.8%)
Required190 (12.4%)
Privileges Required
Low729 (47.7%)
High68 (4.5%)
None687 (45.0%)
Unknown43 (2.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (1527 CVEs).

CISA KEV
15 CVEs
1.0% of CVEs· 99th percentile
Metasploit
4 CVEs
0.3% of CVEs· 97th percentile
Nuclei
2 CVEs
0.1% of CVEs· 95th percentile
ExploitDB
36 CVEs
2.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Samsung.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Samsung — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Samsung's Products

View all 12 CNAs →

Top CWEs