VYPR

Pay

by Samsung Mobile

CVEs (6)

  • CVE-2024-20850MedApr 2, 2024
    risk 0.40cvss 6.2epss 0.00

    Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay.

  • CVE-2022-36872MedSep 9, 2022
    risk 0.33cvss 5.0epss 0.00

    Pending Intent hijacking vulnerability in SpayNotification in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

  • CVE-2022-36871MedSep 9, 2022
    risk 0.33cvss 5.0epss 0.00

    Pending Intent hijacking vulnerability in NotiCenterUtils in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

  • CVE-2022-36870MedSep 9, 2022
    risk 0.33cvss 5.0epss 0.00

    Pending Intent hijacking vulnerability in MTransferNotificationManager in Samsung Pay prior to version 5.0.63 for KR and 5.1.47 for Global allows attackers to access files without permission via implicit Intent.

  • CVE-2021-25527LowDec 8, 2021
    risk 0.25cvss 3.8epss 0.00

    Improper export of Android application components vulnerability in Samsung Pay (India only) prior to version 4.1.77 allows attacker to access Bill Pay and Recharge menu without authentication.

  • CVE-2021-25525LowDec 8, 2021
    risk 0.13cvss 2.0epss 0.00

    Improper check or handling of exception conditions vulnerability in Samsung Pay (US only) prior to version 4.0.65 allows attacker to use NFC without user recognition.