Vendor CVEs
Samsung Pay
All CVEs
310 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-34654 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege. | ||
| CVE-2024-34651 | Med | 0.40 | 6.2 | 0.00 | Sep 4, 2024 | Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files. | ||
| CVE-2024-34608 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34606 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-34604 | Med | 0.40 | 6.2 | 0.00 | Aug 7, 2024 | Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background. | ||
| CVE-2024-31957 | Med | 0.40 | 6.2 | 0.00 | Jul 9, 2024 | A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length. | ||
| CVE-2024-20893 | Med | 0.40 | 6.1 | 0.00 | Jul 2, 2024 | Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption. | ||
| CVE-2024-20886 | Med | 0.40 | 6.2 | 0.00 | Jun 4, 2024 | Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory. | ||
| CVE-2024-20876 | Med | 0.40 | 6.1 | 0.00 | Jun 4, 2024 | Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption. | ||
| CVE-2024-20872 | Med | 0.40 | 6.2 | 0.00 | May 7, 2024 | Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE. | ||
| CVE-2024-20850 | Med | 0.40 | 6.2 | 0.00 | Apr 2, 2024 | Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay. | ||
| CVE-2020-22181 | Med | 0.40 | 6.1 | 0.00 | Aug 22, 2023 | A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi | ||
| CVE-2022-33718 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data. | ||
| CVE-2022-33714 | Med | 0.40 | 6.2 | 0.00 | Aug 5, 2022 | Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot. | ||
| CVE-2020-7811 | Med | 0.40 | 6.2 | 0.01 | Oct 12, 2020 | Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication | ||
| CVE-2026-20982 | Med | 0.39 | 6.0 | 0.00 | Feb 4, 2026 | Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege. | ||
| CVE-2023-21478 | Med | 0.39 | 6.0 | 0.00 | Sep 3, 2025 | Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data. | ||
| CVE-2025-21010 | Med | 0.39 | 6.0 | 0.00 | Aug 6, 2025 | Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account. | ||
| CVE-2024-27382 | Med | 0.39 | 6.0 | 0.00 | Jun 5, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame(), there is no input validation check on len coming from userspace, which can lead to a heap over-read. | ||
| CVE-2024-27381 | Med | 0.39 | 6.0 | 0.00 | Jun 5, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_ut(), there is no input validation check on len coming from userspace, which can lead to a heap over-read. | ||
| CVE-2024-27378 | Med | 0.39 | 6.0 | 0.00 | Jun 5, 2024 | An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_cert(), there is no input validation check on len coming from userspace, which can lead to a heap over-read. | ||
| CVE-2025-52517 | Med | 0.38 | 5.9 | 0.00 | Jan 5, 2026 | An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in a double free, leading to a denial of service. | ||
| CVE-2024-34678 | Med | 0.38 | 5.9 | 0.00 | Nov 6, 2024 | Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption. | ||
| CVE-2024-34601 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore. | ||
| CVE-2024-34586 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy. | ||
| CVE-2024-20889 | Med | 0.38 | 5.9 | 0.00 | Jul 2, 2024 | Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices. | ||
| CVE-2022-26094 | Med | 0.38 | 5.9 | 0.01 | Apr 11, 2022 | Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker. | ||
| CVE-2024-20866 | Med | 0.37 | 5.7 | 0.00 | May 7, 2024 | Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step. | ||
| CVE-2026-21016 | Med | 0.36 | 5.5 | 0.00 | May 13, 2026 | Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information. | ||
| CVE-2025-62815 | Med | 0.36 | 5.5 | 0.00 | Mar 3, 2026 | An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.ast.thread_ref in set_cpu_affinity() causes a denial of service. | ||
| CVE-2026-20977 | Med | 0.36 | 5.5 | 0.00 | Feb 4, 2026 | Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning. | ||
| CVE-2025-58345 | Med | 0.36 | 5.5 | 0.00 | Feb 3, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_certif_11ax_mode write… | ||
| CVE-2025-58343 | Med | 0.36 | 5.5 | 0.00 | Feb 3, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/create_tspec write… | ||
| CVE-2025-20969 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows local attackers to access data within Samsung Gallery. | ||
| CVE-2025-20961 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege. | ||
| CVE-2025-20955 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images. | ||
| CVE-2025-20954 | Med | 0.36 | 5.5 | 0.00 | May 7, 2025 | Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20948 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory. | ||
| CVE-2025-20947 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20935 | Med | 0.36 | 5.5 | 0.00 | Apr 8, 2025 | Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User interaction is required for triggering this vulnerability. | ||
| CVE-2025-20926 | Med | 0.36 | 5.5 | 0.00 | Mar 6, 2025 | Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local attackers to access files with My Files' privilege. | ||
| CVE-2025-20906 | Med | 0.36 | 5.5 | 0.00 | Feb 4, 2025 | Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB. | ||
| CVE-2024-20896 | Med | 0.36 | 5.5 | 0.00 | Jul 2, 2024 | Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information. | ||
| CVE-2024-20864 | Med | 0.36 | 5.5 | 0.00 | May 7, 2024 | Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources. | ||
| CVE-2022-25815 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2022 | PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent. | ||
| CVE-2021-25413 | Med | 0.36 | 5.5 | 0.00 | Jun 11, 2021 | Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbitrary data with Samsung Contacts privilege. | ||
| CVE-2019-20550 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2020 | An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019). | ||
| CVE-2026-21075 | Med | 0.34 | — | 0.00 | Aug 10, 2026 | Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information. | ||
| CVE-2025-53965 | Med | 0.34 | 5.3 | 0.00 | Dec 3, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to decode the SOR transparent container… | ||
| CVE-2025-54331 | Med | 0.34 | 5.3 | 0.00 | Nov 4, 2025 | An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function. |
- risk 0.40cvss 6.2epss 0.00
Improper Export of android application component in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access files with My Files' privilege.
- risk 0.40cvss 6.2epss 0.00
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to access restricted data in My Files.
- risk 0.40cvss 6.2epss 0.00
Improper access control in PaymentManagerService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in SmartThingsService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
Improper access control in LedCoverService prior to SMR Aug-2024 Release 1 allows local attackers to bypass restrictions on starting services from the background.
- risk 0.40cvss 6.2epss 0.00
A vulnerability was discovered in Samsung Mobile Processors Exynos 2200 and Exynos 2400 where they lack a check for the validation of native handles, which can result in a DoS(Denial of Service) attack by unmapping an invalid length.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in libmediaextractorservice.so prior to SMR Jul-2024 Release 1 allows local attackers to trigger memory corruption.
- risk 0.40cvss 6.2epss 0.00
Arbitrary directory creation in Samsung Live Wallpaper PC prior to version 3.3.8.0 allows attacker to create arbitrary directory.
- risk 0.40cvss 6.1epss 0.00
Improper input validation in libsheifdecadapter.so prior to SMR Jun-2024 Release 1 allows local attackers to lead to memory corruption.
- risk 0.40cvss 6.2epss 0.00
Improper handling of insufficient privileges vulnerability in TalkbackSE prior to version Android 14 allows local attackers to modify setting value of TalkbackSE.
- risk 0.40cvss 6.2epss 0.00
Use of Implicit Intent for Sensitive Communication in Samsung Pay prior to version 5.4.99 allows local attackers to access information of Samsung Pay.
- risk 0.40cvss 6.1epss 0.00
A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi
- risk 0.40cvss 6.2epss 0.00
An improper access control vulnerability in Wi-Fi Service prior to SMR AUG-2022 Release 1 allows untrusted applications to manipulate the list of apps that can use mobile data.
- risk 0.40cvss 6.2epss 0.00
Improper access control vulnerability in SemWifiApBroadcastReceiver prior to SMR Aug-2022 Release 1 allows attacker to reset a setting value related to mobile hotspot.
- risk 0.40cvss 6.2epss 0.01
Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication
- risk 0.39cvss 6.0epss 0.00
Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.
- risk 0.39cvss 6.0epss 0.00
Improper input validation vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.
- risk 0.39cvss 6.0epss 0.00
Improper privilege management in SamsungAccount prior to SMR Aug-2025 Release 1 allows local privileged attackers to deactivate Samsung account.
- risk 0.39cvss 6.0epss 0.00
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame(), there is no input validation check on len coming from userspace, which can lead to a heap over-read.
- risk 0.39cvss 6.0epss 0.00
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_ut(), there is no input validation check on len coming from userspace, which can lead to a heap over-read.
- risk 0.39cvss 6.0epss 0.00
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_send_action_frame_cert(), there is no input validation check on len coming from userspace, which can lead to a heap over-read.
- risk 0.38cvss 5.9epss 0.00
An issue was discovered in the Camera in Samsung Mobile Processor and Wearable Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500. A race condition in the issimian device driver results in a double free, leading to a denial of service.
- risk 0.38cvss 5.9epss 0.00
Out-of-bounds write in libsapeextractor.so prior to SMR Nov-2024 Release 1 allows local attackers to cause memory corruption.
- risk 0.38cvss 5.9epss 0.00
Improper verification of intent by broadcast receiver vulnerability in GalaxyStore prior to version 4.5.81.0 allows local attackers to launch unexported activities of GalaxyStore.
- risk 0.38cvss 5.9epss 0.00
Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.
- risk 0.38cvss 5.9epss 0.00
Improper authentication in BLE prior to SMR Jul-2024 Release 1 allows adjacent attackers to pair with devices.
- risk 0.38cvss 5.9epss 0.01
Null pointer dereference vulnerability in parser_auxC function in libsimba library prior to SMR Apr-2022 Release 1 allows out of bounds write by remote attacker.
- risk 0.37cvss 5.7epss 0.00
Authentication bypass vulnerability in Setupwizard prior to SMR May-2024 Release 1 allows physical attackers to skip activation step.
- risk 0.36cvss 5.5epss 0.00
Incorrect privilege assignment in LocationManager prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in Samsung Mobile Processor Exynos 1380, 1480, 2400, 1580, and 2500. A NULL pointer dereference of npu_proto_drv.ast.thread_ref in set_cpu_affinity() causes a denial of service.
- risk 0.36cvss 5.5epss 0.00
Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/ap_certif_11ax_mode write…
- risk 0.36cvss 5.5epss 0.00
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1080, 1280, 1330, 1380, 1480, 1580, W920, W930 and W1000. There is unbounded memory allocation via a large buffer in a /proc/driver/unifi0/create_tspec write…
- risk 0.36cvss 5.5epss 0.00
Improper input validation in Samsung Gallery prior to version 14.5.10.3 in Global Android 13, 14.5.09.3 in China Android 13, and 15.5.04.5 in Android 14 allows local attackers to access data within Samsung Gallery.
- risk 0.36cvss 5.5epss 0.00
Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.
- risk 0.36cvss 5.5epss 0.00
Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.
- risk 0.36cvss 5.5epss 0.00
Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Out-of-bounds read in enrollment with cdsp frame secfr trustlet prior to SMR Apr-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
- risk 0.36cvss 5.5epss 0.00
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access image files across multiple users. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Improper handling of insufficient permission or privileges in ClipboardService prior to SMR Apr-2025 Release 1 allows local attackers to access files with system privilege. User interaction is required for triggering this vulnerability.
- risk 0.36cvss 5.5epss 0.00
Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local attackers to access files with My Files' privilege.
- risk 0.36cvss 5.5epss 0.00
Improper Export of Android Application Components in Settings prior to SMR Feb-2025 Release 1 allows local attackers to enable ADB.
- risk 0.36cvss 5.5epss 0.00
Use of implicit intent for sensitive communication in Configuration message prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.
- risk 0.36cvss 5.5epss 0.00
Improper access control vulnerability in DarManagerService prior to SMR May-2024 Release 1 allows local attackers to monitor system resources.
- risk 0.36cvss 5.5epss 0.00
PendingIntent hijacking vulnerability in Weather application prior to SMR Mar-2022 Release 1 allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
- risk 0.36cvss 5.5epss 0.00
Improper sanitization of incoming intent in Samsung Contacts prior to SMR JUN-2021 Release 1 allows local attackers to get permissions to access arbitrary data with Samsung Contacts privilege.
- risk 0.36cvss 5.5epss 0.00
An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).
- risk 0.34cvss —epss 0.00
Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Modem 5300, and Modem 5400. The function used to decode the SOR transparent container…
- risk 0.34cvss 5.3epss 0.00
An issue was discovered in NPU in Samsung Mobile Processor Exynos 1380 through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function.
Page 4 of 7