Samsung Pay
by Samsung Pay
Source repositories
CVEs (331)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-20972 | Low | 0.21 | 3.3 | 0.00 | Jan 9, 2026 | Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB. | ||
| CVE-2025-21024 | Low | 0.21 | 3.3 | 0.00 | Aug 6, 2025 | Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information. | ||
| CVE-2024-34640 | Low | 0.21 | 3.3 | 0.00 | Sep 4, 2024 | Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration. | ||
| CVE-2022-36834 | Low | 0.21 | 3.3 | 0.00 | Aug 5, 2022 | Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction. | ||
| CVE-2022-30753 | Low | 0.21 | 3.3 | 0.00 | Jul 12, 2022 | Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission. | ||
| CVE-2021-25505 | Low | 0.21 | 3.3 | 0.01 | Nov 5, 2021 | Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked. | ||
| CVE-2021-25455 | Low | 0.21 | 3.3 | 0.00 | Sep 9, 2021 | OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file. | ||
| CVE-2021-25333 | Low | 0.21 | 3.2 | 0.00 | Mar 4, 2021 | Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code. | ||
| CVE-2021-25332 | Low | 0.21 | 3.2 | 0.00 | Mar 4, 2021 | Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition. | ||
| CVE-2021-25331 | Low | 0.21 | 3.2 | 0.00 | Mar 4, 2021 | Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition. | ||
| CVE-2019-20625 | Low | 0.21 | 3.3 | 0.00 | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-2018-13427 (February 2019). | ||
| CVE-2019-20533 | Low | 0.21 | 3.3 | 0.00 | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (released in China or India) software. The S Secure app can launch masked apps without a password. The Samsung ID is SVE-2019-13996 (December 2019). | ||
| CVE-2021-25454 | Low | 0.20 | 3.1 | 0.00 | Sep 9, 2021 | OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file. | ||
| CVE-2023-37366 | Low | 0.18 | 2.8 | 0.00 | Sep 14, 2026 | An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123,… | ||
| CVE-2026-20989 | Low | 0.16 | 2.4 | 0.00 | Mar 16, 2026 | Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font. | ||
| CVE-2024-34649 | Low | 0.16 | 2.4 | 0.00 | Sep 4, 2024 | Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen. | ||
| CVE-2024-20855 | Low | 0.16 | 2.4 | 0.00 | May 7, 2024 | Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while. | ||
| CVE-2021-25486 | Low | 0.16 | 2.5 | 0.00 | Oct 6, 2021 | Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log. | ||
| CVE-2021-25409 | Low | 0.16 | 2.4 | 0.00 | Jun 11, 2021 | Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device. | ||
| CVE-2026-21109 | Low | 0.14 | — | 0.00 | Sep 9, 2026 | Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information. |
- risk 0.21cvss 3.3epss 0.00
Improper Export of Android Application Components in UwbTest prior to SMR Jan-2026 Release 1 allows local attackers to enable UWB.
- risk 0.21cvss 3.3epss 0.00
Use of Implicit Intent for Sensitive Communication in Smart View prior to Android 16 allows local attackers to access sensitive information.
- risk 0.21cvss 3.3epss 0.00
Improper access control vulnerability in BGProtectManager prior to SMR Sep-2024 Release 1 allows local attackers to bypass restriction of process expiration.
- risk 0.21cvss 3.3epss 0.00
Exposure of Sensitive Information vulnerability in Game Launcher prior to version 6.0.07 allows local attacker to access app data with user interaction.
- risk 0.21cvss 3.3epss 0.00
Improper use of a unique device ID in unprotected SecSoterService prior to SMR Jul-2022 Release 1 allows local attackers to get the device ID without permission.
- risk 0.21cvss 3.3epss 0.01
Improper authentication in Samsung Pass prior to 3.0.02.4 allows to use app without authentication when lockscreen is unlocked.
- risk 0.21cvss 3.3epss 0.00
OOB read vulnerability in libsaviextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to access arbitrary address through pointer via forged avi file.
- risk 0.21cvss 3.2epss 0.00
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen via scanning specific QR code.
- risk 0.21cvss 3.2epss 0.00
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to contacts information over the lockscreen in specific condition.
- risk 0.21cvss 3.2epss 0.00
Improper access control in Samsung Pay mini application prior to v4.0.14 allows unauthorized access to balance information over the lockscreen in specific condition.
- risk 0.21cvss 3.3epss 0.00
An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-2018-13427 (February 2019).
- risk 0.21cvss 3.3epss 0.00
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (released in China or India) software. The S Secure app can launch masked apps without a password. The Samsung ID is SVE-2019-13996 (December 2019).
- risk 0.20cvss 3.1epss 0.00
OOB read vulnerability in libsaacextractor.so library prior to SMR Sep-2021 Release 1 allows attackers to execute remote DoS via forged aac file.
- risk 0.18cvss 2.8epss 0.00
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 9110, Exynos W920, Exynos Modem 5123,…
- risk 0.16cvss 2.4epss 0.00
Improper verification of cryptographic signature in Font Settings prior to SMR Mar-2026 Release 1 allows physical attackers to use custom font.
- risk 0.16cvss 2.4epss 0.00
Improper access control in new Dex Mode in multitasking framework prior to SMR Sep-2024 Release 1 allows physical attackers to temporarily access an unlocked screen.
- risk 0.16cvss 2.4epss 0.00
Improper access control vulnerability in multitasking framework prior to SMR May-2024 Release 1 allows physical attackers to access unlocked screen for a while.
- risk 0.16cvss 2.5epss 0.00
Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log.
- risk 0.16cvss 2.4epss 0.00
Improper access in Notification setting prior to SMR JUN-2021 Release 1 allows physically proximate attackers to set arbitrary notification via physically configuring device.
- risk 0.14cvss —epss 0.00
Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information.
Page 16 of 17