Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Op Tee HIGH 7.1
CVE-2021-36133

The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the No…

Mitigation only
Fix from $1,950 2021-12-07
Op Tee CRITICAL 9.1
CVE-2019-25052

In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, cau…

Fix: 3.7.0+
Fix from $2,300 2021-08-11
Trusted Firmware M MEDIUM 5.5
CVE-2021-27562 KEV

In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when c…

Fix: after 1.2.0
Fix from $1,600 2021-05-25
Trusted Firmware M HIGH 7.5
CVE-2021-32032

In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can preven…

Fix: after 1.3.0
Fix from $1,950 2021-05-21
Op Tee CRITICAL 9.8
CVE-2019-1010292

Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks. The impact is: This could lead to corruption of any memory which the TA…

Fix: 3.4.0+
Fix from $2,300 2019-07-16
Op Tee CRITICAL 9.8
CVE-2019-1010293

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee…

Fix: after 3.3.0
Fix from $2,300 2019-07-15
Op Tee CRITICAL 9.8
CVE-2019-1010295

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The compon…

Fix: after 3.3.0
Fix from $2,300 2019-07-15
Op Tee CRITICAL 9.8
CVE-2019-1010296

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component …

Fix: after 3.3.0
Fix from $2,300 2019-07-15
Op Tee CRITICAL 9.8
CVE-2019-1010297

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Execution of code in TEE core (kernel) context. The component …

Fix: after 3.3.0
Fix from $2,300 2019-07-15
Op Tee CRITICAL 9.8
CVE-2019-1010298

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The compon…

Fix: after 3.3.0
Fix from $2,300 2019-07-15
Op Tee HIGH 7.5
CVE-2019-1010294

Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Rounding error. The impact is: Potentially leaking code and/or data from previous Trusted Appl…

Fix: after 3.3.0
Fix from $1,950 2019-07-15
Trusted Firmware A MEDIUM 5.3
CVE-2018-19440

ARM Trusted Firmware-A allows information disclosure.

Fix: after 2.0
Fix from $1,600 2019-01-30
Trusted Firmware A HIGH 7.5
CVE-2017-15031

In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world ti…

Fix: after 2.1
Fix from $1,950 2018-12-18
Trusted Firmware A HIGH 7.0
CVE-2017-9607

The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_…

Fix: after 1.3
Fix from $1,950 2017-09-20
Trusted Firmware A HIGH 8.1
CVE-2017-7563

In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mecha…

Fix: after 1.3
Fix from $1,950 2017-06-07
Trusted Firmware A HIGH 7.5
CVE-2017-7564

In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secu…

Fix: after 1.3
Fix from $1,950 2017-06-07
Mbed Tls HIGH 8.1
CVE-2017-2784

An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and…

Fix: after 1.3.18
Fix from $1,950 2017-04-20
Op Tee HIGH 7.5
CVE-2016-6129

The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equ…

Fix: 2.2.0+
Fix from $1,950 2017-02-13