← Back

Trustedcomputinggroup

trustedcomputinggroup

6 CVEs • 2 products

Products (2)

Click to collapse
Toggle

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Microsoft
Trustedcomputinggroup
12Trusted Platform Module
Windows 10 1507Windows 10 1607+9 more
Nov 4, 2025
Feb 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit th...Show more
An out-of-bounds write vulnerability exists in TPM2.0's Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in the TPM context.Show less
2Microsoft
Trustedcomputinggroup
12Trusted Platform Module
Windows 10 1507Windows 10 1607+9 more
Nov 4, 2025
Feb 28, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnera...Show more
An out-of-bounds read vulnerability exists in TPM2.0's Module Library allowing a 2-byte read past the end of a TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can read or access sensitive data stored in the TPM.Show less
1Trustedcomputinggroup
1Trusted Platform Module
Nov 21, 2024
Nov 18, 2020
N/A· v4
6.0 MEDIUM· v3
3.6 LOW· v2
Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper i...Show more
Trusted Computing Group (TCG) Trusted Platform Module Library Family 2.0 Library Specification Revisions 1.38 through 1.59 has Incorrect Access Control during a non-orderly TPM shut-down that uses USE_DA_USED. Improper initialization of this shut-down may result in susceptibility to a dictionary attack.Show less
2Fedoraproject
Trustedcomputinggroup
2Fedora
Trousers
Nov 21, 2024
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt exis...Show more
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.Show less
1Trustedcomputinggroup
1Trusted Platform Module
Nov 21, 2024
Aug 17, 2018
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an obscure portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification....Show more
An issue was discovered that affects all producers of BIOS firmware who make a certain realistic interpretation of an obscure portion of the Trusted Computing Group (TCG) Trusted Platform Module (TPM) 2.0 specification. An abnormal case is not handled properly by this firmware while S3 sleep and can clear TPM 2.0. It allows local users to overwrite static PCRs of TPM and neutralize the security features of it, such as seal/unseal and remote attestation.Show less
1Trustedcomputinggroup
1Trousers
Apr 29, 2026
Nov 26, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003.