Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Op Tee MEDIUM 5.5
CVE-2026-44362

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,600 2026-07-06
Op Tee MEDIUM 5.5
CVE-2026-40257

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,600 2026-07-06
Op Tee MEDIUM 5.5
CVE-2026-45702

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,600 2026-06-03
Op Tee HIGH 7.8
CVE-2026-40290

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,950 2026-06-03
Op Tee HIGH 7.5
CVE-2026-33662

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,950 2026-04-24
Op Tee HIGH 8.7
CVE-2026-33317

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: after 4.10.0
Fix from $1,950 2026-04-24
Mbed Tls HIGH 7.5
CVE-2026-34876

An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls_ccm_finish() in library/ccm.c allows attackers t…

Fix: 3.6.6+
Fix from $1,950 2026-04-02
Mbed Tls CRITICAL 9.1
CVE-2026-34873

An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resuming a TLS 1.3 session.

Fix: 3.6.6 / 4.1.0+
Fix from $2,300 2026-04-01
Mbed Tls HIGH 7.5
CVE-2026-34874

An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0.0. There is a NULL pointer dereference in distinguished name parsing that allow…

Fix: 3.6.6+
Fix from $1,950 2026-04-01
Mbed Tls HIGH 7.5
CVE-2026-25833

Mbed TLS 3.5.0 to 3.6.5 fixed in 3.6.6 and 4.1.0 has a buffer overflow in the x509_inet_pton_ipv6() function

Fix: 3.6.6+
Fix from $1,950 2026-04-01
Mbed Tls CRITICAL 9.8
CVE-2026-34875

An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0. A buffer overflow can occur in public key export for FFDH keys.

Fix: 1.1.0 / 3.6.6+
Fix from $2,300 2026-04-01
Mbed Tls MEDIUM 6.5
CVE-2026-25834

Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.

Fix: 3.6.6+
Fix from $1,600 2026-04-01
Mbed Tls MEDIUM 6.5
CVE-2025-49601

In MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is at least 4 bytes before reading a 32-bit field, …

Fix: 3.6.4+
Fix from $1,600 2025-07-04
Mbed Tls CRITICAL 9.8
CVE-2024-49195

Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair

Fix: 3.6.2+
Fix from $2,300 2024-10-15
Mbed Tls CRITICAL 9.8
CVE-2024-45158

An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur …

Mitigation only
Fix from $2,300 2024-09-05
Mbed Tls CRITICAL 9.8
CVE-2024-45159

An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provid…

Fix: 3.6.1+
Fix from $2,300 2024-09-05
Mbed Tls MEDIUM 5.1
CVE-2024-45157

An issue was discovered in Mbed TLS before 2.28.9 and 3.x before 3.6.1, in which the user-selected algorithm is not used. Unlike previously documente…

Fix: 2.28.9 / 3.6.1+
Fix from $1,600 2024-09-05
Mbed Tls CRITICAL 9.1
CVE-2024-30166

In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack buffer ov…

Fix: 3.6.0+
Fix from $2,300 2024-04-03
Mbed Tls MEDIUM 6.5
CVE-2024-28755

An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When an SSL context was reset with the mbedtls_ssl_session_reset() API, the maximum TLS versi…

Fix: after 3.6.0
Fix from $1,600 2024-04-03
Mbed Tls MEDIUM 5.4
CVE-2024-28836

An issue was discovered in Mbed TLS 3.5.x before 3.6.0. When negotiating the TLS version on the server side, it can fall back to the TLS 1.2 implemen…

Fix: 3.6.0+
Fix from $1,600 2024-04-03
Mbed Tls HIGH 7.5
CVE-2024-23744

An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

Fix: after 3.5.1
Fix from $1,950 2024-01-21
Mbed Tls CRITICAL 9.8
CVE-2023-45199

Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.

Fix: 3.5.0+
Fix from $2,300 2023-10-07
Op Tee MEDIUM 6.7
CVE-2023-41325

OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone…

Fix: 3.22.0+
Fix from $1,600 2023-09-15
Trusted Firmware M HIGH 7.5
CVE-2023-40271

In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface …

No fix yet
Fix from $1,950 2023-09-08
Trusted Firmware A HIGH 7.4
CVE-2022-47630

Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates. This affects downstream use of get_ext an…

Fix: after 2.8
Fix from $1,950 2023-01-16
Op Tee MEDIUM 6.4
CVE-2022-47549

An unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allows a physi…

Fix: 3.20+
Fix from $1,600 2022-12-19
Op Tee HIGH 8.8
CVE-2022-46152

OP-TEE Trusted OS is the secure side implementation of OP-TEE project, a Trusted Execution Environment. Versions prior to 3.19.0, contain an Improper…

Fix: 3.19.0+
Fix from $1,950 2022-11-29
Trusted Firmware M HIGH 7.8
CVE-2021-43619

Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SP…

Patch available
Fix from $1,950 2022-03-01
Trusted Firmware M MEDIUM 5.9
CVE-2021-40327

Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key (held by the Crypto service) …

Patch available
Fix from $1,600 2022-01-13
Op Tee HIGH 7.8
CVE-2021-44149

An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security acce…

Fix: after 3.15.0
Fix from $1,950 2021-12-07