VYPR

Samsung Pay

by Samsung Pay

CVEs (310)

  • CVE-2022-33717MedAug 5, 2022
    risk 0.29cvss 4.4epss 0.00

    A missing input validation before memory read in SEM TA prior to SMR Aug-2022 Release 1 allows local attackers to read out of bound memory.

  • CVE-2022-22286MedJan 10, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows attackers to execute privileged action by hijacking and modifying the intent.

  • CVE-2025-21016MedAug 6, 2025
    risk 0.28cvss 4.3epss 0.00

    Improper access control in PkgPredictorService prior to SMR Aug-2025 Release 1 in Chinese Android 13, 14, 15 and 16 allows local attackers to use the privileged APIs.

  • CVE-2022-27841MedApr 11, 2022
    risk 0.28cvss 4.3epss 0.00

    Improper exception handling in Samsung Pass prior to version 3.7.07.5 allows physical attacker to view the screen that is previously running without authentication

  • CVE-2016-11050MedApr 7, 2020
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attacker can rewrite the IMEI by flashing crafted firmware. The Samsung ID is SVE-2016-5562 (March 2016).

  • CVE-2018-14853MedDec 17, 2018
    risk 0.28cvss 4.3epss 0.01

    A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device to…

  • CVE-2025-20886MedFeb 4, 2025
    risk 0.27cvss 4.1epss 0.00

    Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.

  • CVE-2024-20873MedJun 4, 2024
    risk 0.27cvss 4.2epss 0.00

    Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2024-20833MedMar 5, 2024
    risk 0.27cvss 4.1epss 0.00

    Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.

  • CVE-2022-25820MedMar 10, 2022
    risk 0.27cvss 4.2epss 0.00

    A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.

  • CVE-2021-25476MedOct 6, 2021
    risk 0.27cvss 4.1epss 0.00

    An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.

  • CVE-2025-21033MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2023-21471MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.

  • CVE-2025-21015MedAug 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

  • CVE-2025-20962MedMay 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.

  • CVE-2025-20950MedApr 8, 2025
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.

  • CVE-2024-34679MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.

  • CVE-2024-34670MedOct 8, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.

  • CVE-2024-34652MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

  • CVE-2024-34647MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

Page 13 of 16