VYPR

Samsung Pay

by Samsung Pay

Source repositories

CVEs (331)

  • CVE-2018-14853MedDec 17, 2018
    risk 0.28cvss 4.3epss 0.01

    A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause the device to…

  • CVE-2026-23791MedSep 14, 2026
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. An out-of-bounds write vulnerability in the Exynos DPU driver (due to missing input length validation in color mode LUT parsing) leads to kernel memory…

  • CVE-2026-23790MedSep 14, 2026
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A double-free vulnerability in the Samsung Exynos DPU driver (due to improper pointer management during DMA buffer reallocation) leads to kernel memory…

  • CVE-2025-20886MedFeb 4, 2025
    risk 0.27cvss 4.1epss 0.00

    Inclusion of sensitive information in test code in softsim trustlet prior to SMR Jan-2025 Release 1 allows local privileged attackers to get test key.

  • CVE-2024-20873MedJun 4, 2024
    risk 0.27cvss 4.2epss 0.00

    Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2024-20833MedMar 5, 2024
    risk 0.27cvss 4.1epss 0.00

    Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.

  • CVE-2022-25820MedMar 10, 2022
    risk 0.27cvss 4.2epss 0.00

    A vulnerable design in fingerprint matching algorithm prior to SMR Mar-2022 Release 1 allows physical attackers to perform brute force attack on screen lock password.

  • CVE-2021-25476MedOct 6, 2021
    risk 0.27cvss 4.1epss 0.00

    An information disclosure vulnerability in Widevine TA log prior to SMR Oct-2021 Release 1 allows attackers to bypass the ASLR protection mechanism in TEE.

  • CVE-2025-21033MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control in ContactProvider prior to SMR Sep-2025 Release 1 allows local attackers to access sensitive information.

  • CVE-2023-21471MedSep 3, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper access control vulnerability in SemClipboard prior to SMR Apr-2023 Release 1 allows attackers to read arbitrary files with system permission.

  • CVE-2025-21015MedAug 6, 2025
    risk 0.26cvss 4.0epss 0.00

    Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.

  • CVE-2025-20962MedMay 7, 2025
    risk 0.26cvss 4.0epss 0.00

    Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.

  • CVE-2025-20950MedApr 8, 2025
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in SamsungNotes prior to version 4.4.26.45 allows local attackers to access sensitive information.

  • CVE-2024-34679MedNov 6, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.

  • CVE-2024-34670MedOct 8, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in Sound Assistant prior to version 6.1.0.9 allows local attackers to get sensitive information.

  • CVE-2024-34652MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to access information related to performance including app usage.

  • CVE-2024-34647MedSep 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Incorrect use of privileged API in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to access privileged APIs related to knox without proper license.

  • CVE-2024-20898MedJul 2, 2024
    risk 0.26cvss 4.0epss 0.00

    Use of implicit intent for sensitive communication in SoftphoneClient in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

  • CVE-2024-20879MedJun 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.

  • CVE-2024-20875MedJun 4, 2024
    risk 0.26cvss 4.0epss 0.00

    Improper caller verification vulnerability in SemClipboard prior to SMR June-2024 Release 1 allows local attackers to access arbitrary files.

Page 14 of 17