This hub aggregates every CVE we track for Email, a product in the mobile apps space. Use it to gauge the current risk picture and drill into individual advisories.
13
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM8LOW4HIGH1
Monthly trend
1
0
0
0
0
0
1
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 13 most recently published vulnerabilities affecting Email.
- CVE-2025-21077Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity with Samsung Email privilege.3.3
- CVE-2025-20894Improper access control in Samsung Email prior to version 6.1.97.1 allows physical attackers to access data across multiple user profiles.4.6
- CVE-2024-34636Use of implicit intent for sensitive communication in Samsung Email prior to version 6.1.94.2 allows local attackers to get sensitive information.4.0
- CVE-2024-20867Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive information.5.5
- CVE-2024-20807Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information.3.3
- CVE-2023-42553Improper authorization verification vulnerability in Samsung Email prior to version 6.1.90.4 allows attackers to read sandbox data of email.4.0
- CVE-2023-30729Improper Certificate Validation in Samsung Email prior to version 6.1.82.0 allows remote attacker to intercept the network traffic including sensitive information.8.1
- CVE-2021-25376An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in plain text when STARTTLS negotiation is failed.3.1
- CVE-2021-25375Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attachments of another emails when users open the malicious attachment.6.5
- CVE-2015-1574The Google Email application 4.2.2.0200 for Android allows remote attackers to cause a denial of service (persistent application crash) via a "Content-Disposition: ;" header in an e-mail message.5.0
- CVE-2012-5588The Email Field module 6.x-1.x before 6.x-1.3 for Drupal, when using a field permission module and the field contact field formatter is set to the full or teaser display mode, does not properly che...2.6
- CVE-2012-5587Cross-site scripting (XSS) vulnerability in the Email Field module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via the mailto link.4.3
- CVE-2012-4499The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email the stored address in the entity via unspecified v...5.0
Product normalization is registry-driven with AI assist and human review. How it works