One
Vendor:
First CVE: Apr 22, 2026 · Active for under a year
8
Total CVEs
More Total CVEs than 85% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact One over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2026
3 months ago
Most Recent CVE
Apr 22, 2026
94 days ago
CVE Severity & Scoring
One8 CVEs
100%
All CVEs352,708 CVEs
45%
40%
11%
Medium
Attack Vector
Local8 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required8 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-6839MEDIUM Improper validation of STRING tensor offsets could allows malformed string metadata to trigger out of bounds access during constant tensor import in Samsung Open Source ONE
Affecte | Apr 22, 2026 | 6.6 | 23 | NO | NO |
CVE-2026-41667MEDIUM Integer overflow in constant tensor data size calculation in Samsung Open Source ONE could cause incorrect buffer sizing for large constant nodes.
Affected version is prior to comm | Apr 22, 2026 | 6.6 | 23 | NO | NO |
CVE-2026-41666MEDIUM Integer overflow in tensor copy size calculation in Samsung Open Source ONE could lead to out of bounds access during loop state propagation.
Affected version is prior to commit 1 | Apr 22, 2026 | 6.6 | 23 | NO | NO |
CVE-2026-41664MEDIUM Integer overflow in memory copy size calculation in Samsung Open Source ONE could lead to invalid memory operations with large tensor shapes.
Affected version is prior to commit 1 | Apr 22, 2026 | 6.6 | 23 | NO | NO |
CVE-2026-40450MEDIUM Integer overflow in output tensor copy size calculation in Samsung Open Source ONE could cause incorrect copy length and memory corruption for oversized tensors.
Affected version i | Apr 22, 2026 | 6.6 | 23 | NO | NO |
CVE-2026-40449MEDIUM Integer overflow in buffer size calculation could result in out of bounds memory access when handling large tensors in Samsung Open Source ONE.
Affected version is prior to commit | Apr 22, 2026 | 6.6 | 23 | NO | NO |
CVE-2026-41665MEDIUM Integer overflow in scratch buffer initialization size calculation in Samsung Open Source ONE cause incorrect memory initialization for large intermediate tensors.
Affected version | Apr 22, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-40448MEDIUM Potential Integer overflow in tensor allocation size calculation could lead to insufficient memory allocation for large tensors in Samsung Open Source ONE.
Affected version is prio | Apr 22, 2026 | 5.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CWEs
Versions
No cataloged versions.