Arm
arm
193 CVEs • 141 products
Products (141)
Click to collapseToggle
Products (141)
Click to collapse
CVEs (193)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Feb 14, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c. |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Feb 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a craf...Show more |
2Arm Debian2Debian Linux Mbed TlsNov 21, 2024 Feb 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASS...Show more |
2Arm Intel209Atom C Atom EAtom X3+206 moreMay 28, 2026 Jan 4, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data c...Show more |
13Arm CanonicalDebian+10 more308Atom C Atom EAtom X3+305 moreMay 28, 2026 Jan 4, 2018 N/A· v4 5.6 MEDIUM· v3 4.7 MEDIUM· v2 Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. |
7Arm CanonicalDebian+4 more220Atom C Atom EAtom X3+217 moreMay 6, 2025 Jan 4, 2018 N/A· v4 5.6 MEDIUM· v3 1.9 LOW· v2 Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. |
2Arm Trustedfirmware2Arm Trusted Firmware Trusted Firmware AJun 5, 2026 Sep 20, 2017 N/A· v4 7.0 HIGH· v3 5.1 MEDIUM· v2 The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly...Show more |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Aug 30, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates. NOTE: although mbed...Show more |
2Arm Trustedfirmware2Arm Trusted Firmware Trusted Firmware AJun 8, 2026 Jun 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors involving debug exceptions and debug regist...Show more |
2Arm Trustedfirmware2Arm Trusted Firmware Trusted Firmware AJun 8, 2026 Jun 7, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execu...Show more |
2Arm Trustedfirmware2Mbed Tls Mbed TlsJun 5, 2026 Apr 20, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed...Show more |
6Arm DebianFedoraproject+3 more6Debian Linux FedoraMbed Tls+3 moreJun 5, 2026 Nov 2, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long...Show more |
6Arm DebianFedoraproject+3 more7Debian Linux FedoraLeap+4 moreJun 5, 2026 Nov 2, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly ex...Show more |