CVEs (41)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Arm FedoraprojectTrustedfirmware4Fedora Mbed CryptoMbed Tls+1 moreJun 5, 2026 Mar 29, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory. |
Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension(). |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Jan 31, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext....Show more |
An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions. |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Oct 7, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution. |
3Arm FedoraprojectTrustedfirmware3Fedora Mbed TlsMbed TlsJun 5, 2026 Oct 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow. |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Jan 17, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing a...Show more |
3Arm FedoraprojectTrustedfirmware3Fedora Mbed TlsMbed TlsJun 5, 2026 Dec 15, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL...Show more |
3Arm FedoraprojectTrustedfirmware3Fedora Mbed TlsMbed TlsJun 5, 2026 Dec 15, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) c...Show more |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 5, 2026 Jul 15, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-re...Show more |
3Arm FedoraprojectTrustedfirmware3Fedora Mbed TlsMbed TlsJun 5, 2026 Dec 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted applic...Show more |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 5, 2026 Dec 20, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. |
4Arm DebianFedoraproject+1 more4Debian Linux FedoraMbed Tls+1 moreJun 5, 2026 Apr 15, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the proje...Show more |
4Arm DebianFedoraproject+1 more5Debian Linux FedoraMbed Crypto+2 moreJun 5, 2026 Sep 26, 2019 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel...Show more |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Dec 5, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites. |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 5, 2026 Apr 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input. |
3Arm DebianTrustedfirmware3Debian Linux Mbed TlsMbed TlsJun 5, 2026 Apr 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input. |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Aug 30, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed...Show more |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Apr 20, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed...Show more |
6Arm DebianFedoraproject+3 more6Debian Linux FedoraMbed Tls+3 moreJun 5, 2026 Nov 2, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long...Show more |