Samsung's vulnerability footprint spans a very broad portfolio of consumer electronics, mobile devices, and semiconductor components—including Android devices, custom Exynos processors and firmware—representing one of the largest and most widely deployed attack surfaces in the landscape. Vulnerabilities affecting the vendor skew toward moderate severity outcomes, with the exposure concentrating in Exynos processor firmware and Android implementations through weakness classes including out-of-bounds memory operations and improper input validation, reflecting the complexity of custom silicon and mobile platform integration. The recurrence of memory-safety issues and input-handling flaws across processor and firmware layers underscores the structural challenges of validating hardware-level and low-level software components at scale. Defenders should prioritize firmware updates and device patching across Samsung's mobile ecosystem, where supply-chain coordination and carrier delays often complicate timely remediation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Samsung over time
Signals from CVEs in this vendor scope (1527 CVEs).
1,527 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7399CRITICAL Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system au | Aug 12, 2024 | 9.8 | 98 | YES | YES |
CVE-2025-21042CRITICAL Out-of-bounds write in libimagecodec.quram.so prior to SMR Apr-2025 Release 1 allows remote attackers to execute arbitrary code. | Sep 12, 2025 | 9.8 | 87 | YES | NO |
CVE-2025-4632CRITICAL Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system au | May 13, 2025 | 9.8 | 87 | YES | YES |
CVE-2017-17692HIGH Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child ta | Dec 21, 2017 | 7.5 | 83 | NO | YES |
CVE-2012-4333HIGH Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0 ActiveX controls in Samsung NET-i viewer 1.37.120316 allow | Aug 14, 2012 | 10.0 | 78 | NO | YES |
CVE-2025-21043CRITICAL Out-of-bounds write in libimagecodec.quram.so prior to SMR Sep-2025 Release 1 allows remote attackers to execute arbitrary code. | Sep 12, 2025 | 9.8 | 75 | YES | NO |
CVE-2016-1010HIGH Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, | Mar 12, 2016 | 8.8 | 71 | YES | NO |
CVE-2021-25487HIGH Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dere | Oct 6, 2021 | 7.8 | 63 | YES | NO |
CVE-2021-25372MEDIUM An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access. | Mar 26, 2021 | 6.7 | 60 | YES | NO |
CVE-2021-25337HIGH Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted applications to read or write certain local files. | Mar 4, 2021 | 7.1 | 60 | YES | NO |
Signals from CVEs in this vendor scope (1527 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Samsung.
Media articles that mention a CVE ID that affects a product developed by Samsung — matched by CVE ID, not by vendor name.