CVEs (73)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Dec 5, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites. |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Jul 28, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack. |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Jul 28, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists be...Show more |
ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signed certificates are accepted, when only RS...Show more |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 17, 2026 Apr 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input. |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 17, 2026 Apr 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input. |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Feb 14, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c. |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Feb 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a craf...Show more |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Feb 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASS...Show more |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Aug 30, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed...Show more |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Apr 20, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed...Show more |
6Arm DebianFedoraproject+3 more6Debian Linux FedoraMbed Tls+3 moreJun 5, 2026 Nov 2, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long...Show more |
6Arm DebianFedoraproject+3 more7Debian Linux FedoraLeap+4 moreJun 5, 2026 Nov 2, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly ex...Show more |