VYPR

mPOS TUI trustlet

by Samsung Mobile

CVEs (6)

  • CVE-2023-21499HigMay 4, 2023
    risk 0.53cvss 8.2epss 0.00

    Out-of-bounds write vulnerability in TA_Communication_mpos_encrypt_pin in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to execute arbitrary code.

  • CVE-2025-20905MedFeb 4, 2025
    risk 0.41cvss 6.3epss 0.00

    Out-of-bounds read and write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to read and write out-of-bounds memory.

  • CVE-2025-20904MedFeb 4, 2025
    risk 0.41cvss 6.3epss 0.00

    Out-of-bounds write in mPOS TUI trustlet prior to SMR Feb-2025 Release 1 allows local privileged attackers to cause memory corruption.

  • CVE-2023-21500MedMay 4, 2023
    risk 0.39cvss 6.0epss 0.00

    Double free validation vulnerability in setPinPadImages in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the trustlet memory.

  • CVE-2023-21498MedMay 4, 2023
    risk 0.39cvss 6.0epss 0.00

    Improper input validation vulnerability in setPartnerTAInfo in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to overwrite the trustlet memory.

  • CVE-2023-21497MedMay 4, 2023
    risk 0.29cvss 4.4epss 0.00

    Use of externally-controlled format string vulnerability in mPOS TUI trustlet prior to SMR May-2023 Release 1 allows local attackers to access the memory address.