Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

X Cube Azrt H7rs HIGH 7.5
CVE-2024-50596

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially craf…

No fix yet
Fix from $1,950 2025-04-02
X Cube Azrt H7rs HIGH 7.5
CVE-2024-50597

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially craf…

No fix yet
Fix from $1,950 2025-04-02
X Cube Azrt H7rs CRITICAL 9.8
CVE-2024-45064

A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially cr…

No fix yet
Fix from $2,300 2025-04-02
X Cube Azrt H7rs HIGH 7.5
CVE-2024-50384

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially cr…

No fix yet
Fix from $1,950 2025-04-02
X Cube Azrt H7rs HIGH 7.5
CVE-2024-50385

A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially cr…

No fix yet
Fix from $1,950 2025-04-02
X Cube Azrt H7rs HIGH 7.5
CVE-2024-50594

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially craf…

No fix yet
Fix from $1,950 2025-04-02
X Cube Azrt H7rs HIGH 7.5
CVE-2024-50595

An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0. A specially craf…

No fix yet
Fix from $1,950 2025-04-02
St54 Android Packages Apps Nfc MEDIUM 5.5
CVE-2023-36629

The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

Fix: 130-20230215-23w07p0+
Fix from $1,600 2024-01-09
X Cube Safea1 HIGH 7.5
CVE-2023-50096

STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to the I2C bu…

No fix yet
Fix from $1,950 2024-01-01
Stm32 Mw Usb Host CRITICAL 9.8
CVE-2021-42553

A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when…

Patch available
Fix from $2,300 2022-10-21
J Safe3 Firmware MEDIUM 6.2
CVE-2021-43392

STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets. This is associ…

Mitigation only
Fix from $1,600 2022-03-04
Stsafe J Firmware MEDIUM 6.2
CVE-2021-43393

STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. This is associated with the E…

Mitigation only
Fix from $1,600 2022-03-04
Stm32cube Middleware MEDIUM 6.8
CVE-2021-34259

A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to e…

Fix: after 1.8.0
Fix from $1,600 2021-07-22
Stm32cube Middleware MEDIUM 6.8
CVE-2021-34260

A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attacker…

Fix: after 1.8.0
Fix from $1,600 2021-07-22
Stm32cube Middleware MEDIUM 6.8
CVE-2021-34262

A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackers to ex…

Fix: after 1.8.0
Fix from $1,600 2021-07-22
Stm32cubel4 Firmware HIGH 7.0
CVE-2020-27212

STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control. The flash read-out protection (RDP) can be degraded from RDP lev…

Fix: after 1.16.0
Fix from $1,950 2021-05-21
Stm32cubel4 Firmware MEDIUM 6.1
CVE-2021-29414

STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.

Fix: after 1.17.0
Fix from $1,600 2021-05-21
Stm32cubef0 MEDIUM 5.9
CVE-2020-20949

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulner…

Mitigation only
Fix from $1,600 2021-01-20
Stm32f103 Firmware MEDIUM 6.8
CVE-2020-13466

STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific flash pa…

Fix: after 2020-05-20
Fix from $1,600 2020-08-31
Stm32f1 Firmware HIGH 7.5
CVE-2020-8004

STMicroelectronics STM32F1 devices have Incorrect Access Control.

No fix yet
Fix from $1,950 2020-04-06
Wb55 MEDIUM 6.5
CVE-2019-19192

The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecutive Attr…

Fix: after 1.3.1
Fix from $1,600 2020-02-12
St33tphf2espi Firmware MEDIUM 5.9
CVE-2019-16863

STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing attack beca…

Mitigation only
Fix from $1,600 2019-11-14
Stm32l0 Firmware MEDIUM 6.6
CVE-2019-14238

On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a debug pr…

No fix yet
Fix from $1,600 2019-09-24
Stm32l0 Firmware CRITICAL 9.8
CVE-2019-14236

On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP p…

No fix yet
Fix from $2,300 2019-09-12
Ftp Service MEDIUM 6.4
CVE-2003-0392

Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS drive lette…

Mitigation only
Fix from $1,600 2003-07-02