VYPR

Samsung Pay

by Samsung Pay

CVEs (310)

  • CVE-2026-20977MedFeb 4, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.

  • CVE-2025-58345MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_certif_11ax_mode write…

  • CVE-2025-58343MedFeb 3, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/create_tspec write…

  • CVE-2025-20969MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows local attackers to access data within Samsung Gallery.

  • CVE-2025-20961MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.

  • CVE-2025-20955MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.

  • CVE-2025-20954MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

  • CVE-2025-20948MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.

  • CVE-2025-20947MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.

  • CVE-2025-20935MedApr 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User interaction is required for triggering this vulnerability.

  • CVE-2025-20926MedMar 6, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local attackers to access files with My Files' privilege.

  • CVE-2025-20906MedFeb 4, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.

  • CVE-2024-20896MedJul 2, 2024
    risk 0.36cvss 5.5epss 0.00

    Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-20864MedMay 7, 2024
    risk 0.36cvss 5.5epss 0.00

    Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.

  • CVE-2022-25815MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

  • CVE-2021-25413MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbitrary data with Samsung Contacts privilege.

  • CVE-2019-20550MedMar 24, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).

  • CVE-2026-21075MedAug 10, 2026
    risk 0.34cvss epss 0.00

    Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.

  • CVE-2025-53965MedDec 3, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to decode the SOR transparent container…

  • CVE-2025-54331MedNov 4, 2025
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function.

Page 10 of 16