VYPR

Samsung Pay

by Samsung Pay

CVEs (310)

  • CVE-2024-20850MedApr 2, 2024
    risk 0.40cvss 6.2epss 0.00

    Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay.

  • CVE-2020-22181MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.00

    A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi

  • CVE-2022-33718MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.

  • CVE-2022-33714MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.00

    Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.

  • CVE-2020-7811MedOct 12, 2020
    risk 0.40cvss 6.2epss 0.01

    Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication

  • CVE-2026-20982MedFeb 4, 2026
    risk 0.39cvss 6.0epss 0.00

    Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.

  • CVE-2023-21478MedSep 3, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

  • CVE-2025-21010MedAug 6, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.

  • CVE-2024-27382MedJun 5, 2024
    risk 0.39cvss 6.0epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame(), there is no input validation check on len coming from userspace, which can lead to a heap over-read.

  • CVE-2024-27381MedJun 5, 2024
    risk 0.39cvss 6.0epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_ut(), there is no input validation check on len coming from userspace, which can lead to a heap over-read.

  • CVE-2024-27378MedJun 5, 2024
    risk 0.39cvss 6.0epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_cert(), there is no input validation check on len coming from userspace, which can lead to a heap over-read.

  • CVE-2025-52517MedJan 5, 2026
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in a double free, leading to a denial of service.

  • CVE-2024-34678MedNov 6, 2024
    risk 0.38cvss 5.9epss 0.00

    Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.

  • CVE-2024-34601MedJul 2, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore.

  • CVE-2024-34586MedJul 2, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.

  • CVE-2024-20889MedJul 2, 2024
    risk 0.38cvss 5.9epss 0.00

    Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.

  • CVE-2022-26094MedApr 11, 2022
    risk 0.38cvss 5.9epss 0.01

    Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.

  • CVE-2024-20866MedMay 7, 2024
    risk 0.37cvss 5.7epss 0.00

    Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.

  • CVE-2026-21016MedMay 13, 2026
    risk 0.36cvss 5.5epss 0.00

    Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.

  • CVE-2025-62815MedMar 3, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.ast.thread_ref in set_cpu_affinity() causes a denial of service.

Page 9 of 16