Nxp
nxp
18 CVEs • 213 products
Products (213)
Click to collapseToggle
Products (213)
Click to collapse
CVEs (18)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafted Flattened Image Tree (FIT) format stru...Show more |
1Nxp 23I.mx 6 Firmware I.mx 6dual FirmwareI.mx 6duallite Firmware+20 moreApr 30, 2025 Nov 18, 2022 N/A· v4 4.6 MEDIUM· v3 N/A· v2 An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i.MX RT 1015, i.MX RT 1020, i.MX RT 1050, i.MX RT 1060, i.MX 6 Family, i.MX 7Dual...Show more |
1Nxp 1Mcuxpresso Software Development Kit Nov 21, 2024 May 3, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior s...Show more |
NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memory allocation, resulting in unexpected be...Show more |
1Nxp 6Lpc55s66jbd100 Firmware Lpc55s66jbd64 FirmwareLpc55s66jev98 Firmware+3 moreNov 21, 2024 Mar 23, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates before the signature is verified. This ca...Show more |
NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory. |
1Nxp 3Lpc55s69jbd100 Firmware Lpc55s69jbd64 FirmwareLpc55s69jev98 FirmwareNov 21, 2024 Dec 1, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-System Programming (ISP) mode. This discloses protected flash memory. |
1Nxp 1Mcuxpresso Software Development Kit Nov 21, 2024 Oct 25, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor(). |
1Nxp 1Mcuxpresso Software Development Kit Nov 21, 2024 Oct 25, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback(). |
1Nxp 8Mifare Ultralight C Firmware Mifare Ultralight Ev1 FirmwareMifare Ultralight Nano Firmware+5 moreNov 21, 2024 Jun 6, 2021 N/A· v4 4.2 MEDIUM· v3 1.9 LOW· v2 On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a Monotonic Counter protection mechanism. The impact depends on how the anti tear...Show more |
1Nxp 24I.mx Rt500 Firmware I.mx Rt600 FirmwareLpc5512jbd100 Firmware+21 moreNov 21, 2024 May 6, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon rev 0A, 1B), LPC55S1x, LPC551x (silicon rev 0A) and LPC55S0x, LPC550x (...Show more |
4Ftsafe GoogleNxp+1 more453a081 A7005aJ2a081+42 moreNov 21, 2024 Jan 7, 2021 N/A· v4 4.2 MEDIUM· v3 1.9 LOW· v2 An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.9. It allows attackers to extract the ECD...Show more |
1Nxp 1Mcuxpresso Software Development Kit Nov 21, 2024 Feb 12, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted pack...Show more |
1Nxp 1Mcuxpresso Software Development Kit Nov 21, 2024 Feb 10, 2020 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier) does not properly restrict the BLE Link Layer header and executes cert...Show more |
1Nxp 3Kinetis K8x Firmware Kinetis Kv1x FirmwareKinetis Kv3x FirmwareNov 21, 2024 Sep 24, 2019 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only r...Show more |
1Nxp 3Kinetis K8x Firmware Kinetis Kv1x FirmwareKinetis Kv3x FirmwareNov 21, 2024 Sep 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruct...Show more |
1Nxp 27I.mx 50 Firmware I.mx 53 FirmwareI.mx 6dual Firmware+24 moreMay 13, 2026 Aug 7, 2017 N/A· v4 6.3 MEDIUM· v3 4.4 MEDIUM· v2 A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vyb...Show more |
1Nxp 30I.mx 28 Firmware I.mx 50 FirmwareI.mx 53 Firmware+27 moreMay 13, 2026 Aug 7, 2017 N/A· v4 6.0 MEDIUM· v3 4.4 MEDIUM· v2 An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualL...Show more |