VulnSea

Samsung Opensource has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 6.2 (medium). None have a confirmed exploitation report. Most affected products: Escargot (2), Walrus (2), rLottie (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.2
Publish → KEV
Last 90 days
5 prev 0

Products

  • Escargot 2
  • Walrus 2
  • rLottie 1
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Samsung Opensource vulnerabilities

CVEs affecting Samsung Opensource, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-92259Medium· 5.5
1w ago

Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This is…

Integer overflow or wraparound vulnerability in Samsung Opensource Escargot allows attackers with write access to the bytecode-cache directory to cause a heap-based buffer overflow and denial of service via a crafted cache file. This is…

SunlitSamsung Opensource · EscargotEPSS 0.17%via NVD
CVE-2026-91826Medium· 4.4
1w ago

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b821…

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b821…

SunlitSamsung Opensource · rLottieEPSS 0.11%via NVD
CVE-2026-86314Medium· 6.2
2w ago

Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module…

Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module…

SunlitSamsung Opensource · WalrusEPSS 0.13%via NVD
CVE-2026-86313High· 7.8
2w ago

Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

TwilightSamsung Opensource · WalrusEPSS 0.12%via NVD
CVE-2026-86315Medium· 6.2
2w ago

An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definiti…

An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definiti…

SunlitSamsung Opensource · EscargotEPSS 0.12%via NVD
Samsung Opensource vulnerabilities (CVEs) · VulnSea