Samsung Pay
by Samsung Pay
CVEs (310)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-14852 | Med | 0.41 | 6.3 | 0.01 | Dec 17, 2018 | Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause invalid accesses to operating… | ||
| CVE-2026-20978 | Med | 0.40 | 6.1 | 0.00 | Feb 4, 2026 | Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application. | ||
| CVE-2025-21004 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device. | ||
| CVE-2025-21002 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast. | ||
| CVE-2025-21001 | Med | 0.40 | 6.2 | 0.00 | Jul 8, 2025 | Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast. | ||
| CVE-2025-20981 | Med | 0.40 | 6.2 | 0.00 | Jun 4, 2025 | Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2025-20965 | Med | 0.40 | 6.2 | 0.00 | May 7, 2025 | Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data. | ||
| CVE-2025-20941 | Med | 0.40 | 6.2 | 0.00 | Apr 8, 2025 | Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device. | ||
| CVE-2025-20910 | Med | 0.40 | 6.2 | 0.00 | Mar 6, 2025 | Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery. | ||
| CVE-2024-34655 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager. | ||
| CVE-2024-34654 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege. | ||
| CVE-2024-34651 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files. | ||
| CVE-2024-34608 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34606 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34604 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-31957 | Med | 0.40 | 6.2 | 0.00 | Jul 9, 2024 | A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length. | ||
| CVE-2024-20893 | Med | 0.40 | 6.1 | 0.00 | Jul 2, 2024 | Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption. | ||
| CVE-2024-20886 | Med | 0.40 | 6.2 | 0.00 | Jun 4, 2024 | Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory. | ||
| CVE-2024-20876 | Med | 0.40 | 6.1 | 0.00 | Jun 4, 2024 | Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption. | ||
| CVE-2024-20872 | Med | 0.40 | 6.2 | 0.00 | May 7, 2024 | Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE. |
- risk 0.41cvss 6.3epss 0.01
Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to cause invalid accesses to operating…
- risk 0.40cvss 6.1epss 0.00
Improper authorization in KnoxGuardManager prior to SMR Feb-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.
- risk 0.40cvss 6.2epss 0.00
Improper verification of intent by broadcast receiver in System UI for Galaxy Watch prior to SMR Jul-2025 Release 1 allows local attackers to power off the device.
- risk 0.40cvss 6.2epss 0.00
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to manipulate broadcasting Auracast.
- risk 0.40cvss 6.2epss 0.00
Improper access control in LeAudioService prior to SMR Jul-2025 Release 1 allows local attackers to stop broadcasting Auracast.
- risk 0.40cvss 6.2epss 0.00
Improper access control in AudioService prior to SMR Jun-2025 Release 1 allows local attackers to access sensitive information.
- risk 0.40cvss 6.2epss 0.00
Improper handling of insufficient permission in Bixby wakeup prior to version 2.3.74.8 allows local attackers to access sensitive data.
- risk 0.40cvss 6.2epss 0.00
Improper access control in InputManager to SMR Apr-2025 Release 1 allows local attackers to access the scancode of specific input device.
- risk 0.40cvss 6.2epss 0.00
Incorrect default permission in Galaxy Watch Gallery prior to SMR Mar-2025 Release 1 allows local attackers to access data in Galaxy Watch Gallery.
- risk 0.40cvss 6.2epss 0.00
Incorrect use of privileged API in UniversalCredentialManager prior to SMR Sep-2024 Release 1 allows local attackers to access privileged API related to UniversalCredentialManager.
- risk 0.40cvss 6.2epss 0.00
Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.
- risk 0.40cvss 6.2epss 0.00
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
- risk 0.40cvss 6.2epss 0.00
Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.
- risk 0.40cvss 6.2epss 0.00
Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.
- risk 0.40cvss 6.2epss 0.00
Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.
Page 8 of 16