Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bm78 Firmware HIGH 7.5
CVE-2022-46399

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) is unresponsive with ConReqTimeoutZero.

No fix yet
Fix from $1,950 2022-12-19
Bm78 Firmware MEDIUM 5.4
CVE-2022-46400

The Microchip RN4870 module firmware 1.43 (and the Microchip PIC LightBlue Explorer Demo 4.2 DT100112) allows attackers to bypass passkey entry in le…

No fix yet
Fix from $1,600 2022-12-19
Miwi HIGH 7.5
CVE-2021-37604

In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters being validat…

Mitigation only
Fix from $1,950 2021-08-05
Miwi HIGH 7.5
CVE-2021-37605

In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Inte…

Mitigation only
Fix from $1,950 2021-08-05
Cryptoauthlib MEDIUM 6.8
CVE-2019-16128

Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2).

Fix: 20191122+
Fix from $1,600 2020-10-22
Cryptoauthlib MEDIUM 6.8
CVE-2019-16129

Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2).

Fix: 20191122+
Fix from $1,600 2020-10-22
Advanced Software Framework 4 CRITICAL 9.1
CVE-2019-16127

Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.

No fix yet
Fix from $2,300 2020-10-22
Atsama5d21c Cu Firmware HIGH 7.5
CVE-2020-12787

Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.

Mitigation only
Fix from $1,950 2020-09-14
Atsama5d21c Cu Firmware HIGH 7.5
CVE-2020-12788

CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.

Mitigation only
Fix from $1,950 2020-09-14
Atsama5d21c Cu Firmware HIGH 7.5
CVE-2020-12789

The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.

Mitigation only
Fix from $1,950 2020-09-14
Syncserver S100 Firmware MEDIUM 6.5
CVE-2020-9029

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName paramete…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware MEDIUM 6.5
CVE-2020-9030

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName paramete…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware MEDIUM 6.5
CVE-2020-9031

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName paramete…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware MEDIUM 6.5
CVE-2020-9032

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName paramete…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware MEDIUM 6.5
CVE-2020-9033

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName paramete…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware MEDIUM 6.1
CVE-2020-9028

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on t…

No fix yet
Fix from $1,600 2020-02-17
Syncserver S100 Firmware HIGH 7.5
CVE-2020-9034

Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenti…

No fix yet
Fix from $1,950 2020-02-17
Atmsamb11 Blusdk Smart MEDIUM 6.5
CVE-2019-19195

The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer d…

Fix: after 6.2
Fix from $1,600 2020-02-10
Mplab Ide HIGH 9.3
CVE-2009-1674

Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a…

No fix yet
Fix from $1,950 2009-05-18
Mplab Ide HIGH 9.3
CVE-2009-1608EPSS 11%

Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code vi…

No fix yet
Fix from $1,950 2009-05-11