Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Uboot Secondary Program Loader HIGH 7.8
CVE-2023-39902

A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Und…

Fix: 2023.07+
Fix from $1,950 2023-10-17
Mqx CRITICAL 9.8
CVE-2021-22680

NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignm…

Fix: after 5.1
Fix from $2,300 2022-05-03
Mcuxpresso Software Development Kit CRITICAL 9.8
CVE-2021-27421

NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations ou…

Fix: 2.8.2+
Fix from $2,300 2022-05-03
Lpc55s66jbd64 Firmware HIGH 7.8
CVE-2022-22819

NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer ov…

No fix yet
Fix from $1,950 2022-03-23
Lpc55s69jbd100 Firmware MEDIUM 5.5
CVE-2021-40154

NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of USB In-Sys…

Mitigation only
Fix from $1,600 2021-12-01
Kinetis K82 Firmware MEDIUM 5.5
CVE-2021-44479

NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Programming (IS…

Mitigation only
Fix from $1,600 2021-12-01
Mcuxpresso Software Development Kit HIGH 7.8
CVE-2021-38258

NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().

No fix yet
Fix from $1,950 2021-10-25
Mcuxpresso Software Development Kit HIGH 7.8
CVE-2021-38260

NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor().

No fix yet
Fix from $1,950 2021-10-25
Lpc55s69jbd100 Firmware MEDIUM 6.8
CVE-2021-31532

NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x (silicon …

No fix yet
Fix from $1,600 2021-05-06
Mcuxpresso Software Development Kit HIGH 8.8
CVE-2019-17519

The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing…

Fix: after 2.2.1
Fix from $1,950 2020-02-12
Mcuxpresso Software Development Kit MEDIUM 6.5
CVE-2019-17060

The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and earlier)…

Fix: after 2.2.1
Fix from $1,600 2020-02-10
Kinetis Kv1x Firmware MEDIUM 6.6
CVE-2019-14239

On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can…

No fix yet
Fix from $1,600 2019-09-24
Kinetis Kv1x Firmware CRITICAL 9.8
CVE-2019-14237

On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can…

No fix yet
Fix from $2,300 2019-09-12
Vybrid Mvf30nn151cku26 Firmware MEDIUM 6.3
CVE-2017-7936

A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i…

Mitigation only
Fix from $1,600 2017-08-07
Vybrid Mvf30nn151cku26 Firmware MEDIUM 6.0
CVE-2017-7932

An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6…

Mitigation only
Fix from $1,600 2017-08-07