← Back

St

st

29 CVEs • 305 products

Products (305)

Click to collapse
Toggle
Ftp Service
ftp_service
Wb55
wb55
Bluenrg 2
bluenrg-2

CVEs (29)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1St
10X Cube Azrt H7rs
X Cube Azrtos F4X Cube Azrtos F7+7 more
Nov 3, 2025
Apr 2, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send...Show more
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.cShow less
1St
10X Cube Azrt H7rs
X Cube Azrtos F4X Cube Azrtos F7+7 more
Nov 3, 2025
Apr 2, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send...Show more
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.cShow less
1St
10X Cube Azrt H7rs
X Cube Azrtos F4X Cube Azrtos F7+7 more
Nov 3, 2025
Apr 2, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attack...Show more
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.cShow less
1St
10X Cube Azrt H7rs
X Cube Azrtos F4X Cube Azrtos F7+7 more
Nov 3, 2025
Apr 2, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attack...Show more
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted series of network requests can lead to denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability.This vulnerability affects the NetX Duo Web Component HTTP Server implementation which can be found in x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.cShow less
1St
10X Cube Azrt H7rs
X Cube Azrtos F4X Cube Azrtos F7+7 more
Nov 3, 2025
Apr 2, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can sen...Show more
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Component HTTP Server HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\http\nxd_http_server.cShow less
1St
10X Cube Azrt H7rs
X Cube Azrtos F4X Cube Azrtos F7+7 more
Nov 3, 2025
Apr 2, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can sen...Show more
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability affects X-CUBE-AZRTOS-F7 NetX Duo Web Component HTTP server v 1.1.0. This HTTP server implementation is contained in this file - x-cube-azrtos-f7\Middlewares\ST\netxduo\addons\web\nx_web_http_server.cShow less
1St
10X Cube Azrt H7rs
X Cube Azrtos F4X Cube Azrtos F7+7 more
Sep 5, 2025
Apr 2, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker ca...Show more
A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially crafted set of network packets can lead to code execution. An attacker can send a sequence of requests to trigger this vulnerability.Show less
1St
1St54 Android Packages Apps Nfc
Jun 20, 2025
Jan 9, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.
1St
1X Cube Safea1
Nov 21, 2024
Jan 1, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-C...Show more
STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bus. This is caused by an StSafeA_ReceiveBytes buffer overflow in the X-CUBE-SAFEA1 Software Package for STSAFE-A sample applications (1.2.0), and thus can affect user-written code that was derived from a published sample application.Show less
1St
1Stm32 Mw Usb Host
May 7, 2025
Oct 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. Th...Show more
A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.Show less
1St
2J Safe3 Firmware
Stsafe J Firmware
Nov 21, 2024
Mar 4, 2022
N/A· v4
6.2 MEDIUM· v3
1.9 LOW· v2
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platform...Show more
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. It might also impact other products based on the J-SAFE-3 Java Card platform.Show less
1St
2J Safe3 Firmware
Stsafe J Firmware
Nov 21, 2024
Mar 4, 2022
N/A· v4
6.2 MEDIUM· v3
1.9 LOW· v2
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and ST...Show more
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associated with the ECDSA signature algorithm on the Java Card J-SAFE3 and STSAFE-J platforms exposing a 3.0.4 Java Card API. It is exploitable for STSAFE-J in closed configuration and J-SIGN (when signature verification is activated) but not for J-SAFE3 EPASS BAC and EAC products. It might also impact other products based on the J-SAFE-3 Java Card platform.Show less
1St
1Stm32cube Middleware
Nov 21, 2024
Jul 22, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An issue in the USBH_ParseDevDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) via a malformed USB device packet.
1St
1Stm32cube Middleware
Nov 21, 2024
Jul 22, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An in the USBH_MSC_InterfaceInit() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service (DOS) when the system tries to communicate with the connected endpoint.
1St
1Stm32cube Middleware
Nov 21, 2024
Jul 22, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
1St
1Stm32cube Middleware
Nov 21, 2024
Jul 22, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
An issue in USBH_ParseCfgDesc() of STMicroelectronics STM32Cube Middleware v1.8.0 and below causes a denial of service due to the system hanging when trying to set a remote wake-up feature.
1St
1Stm32cube Middleware
Nov 21, 2024
Jul 22, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
1St
1Stm32cube Middleware
Nov 21, 2024
Jul 22, 2021
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to execute arbitrary code.
1St
1Stm32cubel4 Firmware
Nov 21, 2024
May 21, 2021
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.
1St
1Stm32cubel4 Firmware
Nov 21, 2024
May 21, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via deb...Show more
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP level 2 (no access via debug interface) to level 1 (limited access via debug interface) by injecting a fault during the boot phase.Show less