VYPR

FINGERPRINT Trustlet

by Samsung Mobile

CVEs (7)

  • CVE-2020-11600CriApr 8, 2020
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered on Samsung mobile devices with Q(10.0) software. There is arbitrary code execution in the Fingerprint Trustlet via a memory overwrite. The Samsung IDs are SVE-2019-16587, SVE-2019-16588, SVE-2019-16589 (April 2020).

  • CVE-2025-21072MedDec 2, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in decoding metadata in fingerprint trustlet prior to SMR Dec-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21071MedNov 5, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in handling opcode in fingerprint trustlet prior to SMR Nov-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-21044MedOct 10, 2025
    risk 0.37cvss 5.7epss 0.00

    Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

  • CVE-2025-20988MedJun 4, 2025
    risk 0.36cvss 5.5epss 0.00

    Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.

  • CVE-2025-20989MedJun 4, 2025
    risk 0.34cvss 5.2epss 0.00

    Improper logging in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a hmac_key.

  • CVE-2025-20987MedJun 4, 2025
    risk 0.34cvss 5.2epss 0.00

    Improper access control in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to get a auth_token.