VYPR

Samsung Pay

by Samsung Pay

Source repositories

CVEs (331)

  • CVE-2022-24924LowFeb 11, 2022
    risk 0.14cvss 2.2epss 0.01

    An improper access control in LiveWallpaperService prior to versions 3.0.9.0 allows to create a specific named system directory without a proper permission.

  • CVE-2021-25525LowDec 8, 2021
    risk 0.13cvss 2.0epss 0.00

    Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.

  • CVE-2026-21057MedJul 10, 2026
    risk 0.00cvss —epss 0.00

    Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2026-21054MedJul 10, 2026
    risk 0.00cvss —epss 0.00

    Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.

  • CVE-2026-21052MedJul 10, 2026
    risk 0.00cvss —epss 0.00

    Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.

  • CVE-2026-21050MedJul 10, 2026
    risk 0.00cvss —epss 0.00

    Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.

  • CVE-2026-21046HigJul 10, 2026
    risk 0.00cvss —epss 0.00

    Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2026-21044MedJul 10, 2026
    risk 0.00cvss —epss 0.00

    Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.

  • CVE-2026-21041MedJul 10, 2026
    risk 0.00cvss —epss 0.00

    Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.

  • CVE-2026-21040MedJul 10, 2026
    risk 0.00cvss —epss 0.00

    Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs.

  • CVE-2026-21039MedJul 10, 2026
    risk 0.00cvss —epss 0.00

    Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.

Page 17 of 17