Arm
arm
193 CVEs • 141 products
Products (141)
Click to collapseToggle
Products (141)
Click to collapse
CVEs (193)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A buffer over-read was discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse_multiple_options() parses CoAP opti...Show more |
Buffer over-reads were discovered in the CoAP library in Arm Mbed OS 5.15.3. The CoAP parser is responsible for parsing received CoAP packets. The function sn_coap_parser_options_parse() parses CoAP input linearly using...Show more |
2Arm Opensuse8Cortex A32 Firmware Cortex A34 FirmwareCortex A35 Firmware+5 moreNov 21, 2024 Jun 8, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analys...Show more |
3Arm DebianFedoraproject3Debian Linux FedoraMbed TlsNov 21, 2024 Apr 15, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the proje...Show more |
3Arm DebianFedoraproject4Debian Linux FedoraMbed Crypto+1 moreNov 21, 2024 Mar 24, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import. |
3Arm DebianFedoraproject4Debian Linux FedoraMbed Crypto+1 moreNov 21, 2024 Jan 23, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key v...Show more |
A denial-of-service issue was discovered in the MQTT library in Arm Mbed OS 2017-11-02. The function readMQTTLenString() is called by the function MQTTDeserialize_publish() to get the length and content of the MQTT topic...Show more |
3Arm DebianFedoraproject4Debian Linux FedoraMbed Crypto+1 moreNov 21, 2024 Sep 26, 2019 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel...Show more |
ARM Trusted Firmware-A allows information disclosure. |
In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information. |
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites. |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Jul 28, 2018 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows local users to achieve partial plaintext recovery (for a CBC based ciphersuite) via a cache-based side-channel attack. |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Jul 28, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 ARM mbed TLS before 2.12.0, before 2.7.5, and before 2.1.14 allows remote attackers to achieve partial plaintext recovery (for a CBC based ciphersuite) via a timing-based side-channel attack. This vulnerability exists be...Show more |
7Arm FujitsuIntel+4 more225Atom C Atom EAtom X3+222 moreNov 21, 2024 Jul 10, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel...Show more |
ARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signed certificates are accepted, when only RS...Show more |
2Arm Intel199Atom C Atom EAtom Z+196 moreNov 21, 2024 May 22, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-...Show more |
12Arm CanonicalDebian+9 more282Atom C Atom EAtom X5 E3930+279 moreMay 29, 2026 May 22, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an atta...Show more |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Apr 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_psk_hint() that could cause a crash on invalid input. |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Apr 10, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input. |
2Arm Intel209Atom C Atom EAtom X3+206 moreNov 21, 2024 Mar 27, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demons...Show more |