VYPR

Samsung Pay

by Samsung Pay

CVEs (310)

  • CVE-2024-49413HigDec 3, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Verification of Cryptographic Signature in SmartSwitch prior to SMR Dec-2024 Release 1 allows local attackers to install malicious applications.

  • CVE-2021-25346HigMar 4, 2021
    risk 0.46cvss 7.1epss 0.01

    A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.

  • CVE-2026-21059MedAug 10, 2026
    risk 0.45cvss epss 0.00

    Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

  • CVE-2026-20980MedFeb 4, 2026
    risk 0.44cvss 6.8epss 0.00

    Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.

  • CVE-2026-20968MedJan 9, 2026
    risk 0.44cvss 6.7epss 0.00

    Use after free in DualDAR prior to SMR Jan-2026 Release 1 allows local privileged attackers to execute arbitrary code.

  • CVE-2025-21073MedNov 5, 2025
    risk 0.44cvss 6.8epss 0.00

    Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attackers to access user data. User interaction is required for triggering this vulnerability.

  • CVE-2025-20984MedJun 4, 2025
    risk 0.44cvss 6.8epss 0.00

    Incorrect default permission in Samsung Cloud for Galaxy Watch prior to SMR Jun-2025 Release 1 allows local attackers to access data in Samsung Cloud for Galaxy Watch.

  • CVE-2024-27387MedSep 9, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is no input validation check on rtt_id coming from userspace, which can lead to a heap overwrite.

  • CVE-2024-27386MedJul 9, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite.

  • CVE-2024-27385MedJul 9, 2024
    risk 0.44cvss 6.7epss 0.00

    A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for rx coming from userspace, which can lead to heap overwrite.

  • CVE-2024-31958MedJun 7, 2024
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in Samsung Mobile Processor EExynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in an Out-of-Bounds Write.

  • CVE-2024-27379MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead…

  • CVE-2024-27376MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->rx_match_filter_len coming from userspace, which can lead to…

  • CVE-2024-27375MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->sdea_service_specific_info_len coming from userspace, which…

  • CVE-2024-27374MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_publish_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can lead…

  • CVE-2024-27373MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->mesh_id_len coming from userspace, which can lead to a heap…

  • CVE-2024-27372MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->infrastructure_ssid_len coming from userspace, which can lead…

  • CVE-2024-27371MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_followup_get_nl_params(), there is no input validation check on hal_req->service_specific_info_len coming from userspace, which can…

  • CVE-2024-27370MedJun 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on hal_req->num_config_discovery_attr coming from userspace, which can lead…

  • CVE-2024-20863MedMay 7, 2024
    risk 0.44cvss 6.7epss 0.00

    Out of bounds write vulnerability in SNAP in HAL prior to SMR May-2024 Release 1 allows local privileged attackers to execute arbitrary code.

Page 6 of 16