Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
arm vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2024-23775
Integer Overflow vulnerability in Mbed TLS 2.x prior to 2.28.7 and 3.x prior to 3.5.2, allows malicious users to cause a denial of service (DoS) via mbedtls_x509_set_extension().
Arm Mbed Tls
7.5
CVSSv3
CVE-2023-52353
An issue exists in Mbed TLS up to and including 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.
Arm Mbed Tls
4.7
CVSSv3
CVE-2021-36647
Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions prior to 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (typically an untrusted opera...
Arm Mbed Tls
1 Github repository
7
CVSSv3
CVE-2017-7496
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary directories.
Fedoraproject Arm Installer
7.5
CVSSv3
CVE-2018-1000520
ARM mbedTLS version 2.7.0 and previous versions contains a Ciphersuite Allows Incorrectly Signed Certificates vulnerability in mbedtls_ssl_get_verify_result() that can result in ECDSA-signed certificates are accepted, when only RSA-signed ones should be.. This attack appear to be...
Arm Mbed Tls
4.7
CVSSv3
CVE-2018-19608
Arm Mbed TLS prior to 2.14.1, prior to 2.7.8, and prior to 2.1.17 allows a local unprivileged malicious user to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
Arm Mbed Tls
9.8
CVSSv3
CVE-2021-27431
ARM CMSIS RTOS2 versions before 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution.
Arm Cmsis-rtos
9.8
CVSSv3
CVE-2021-27435
ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Arm Mbed 6.3.0
7.8
CVSSv3
CVE-2020-16273
In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by a stack-underflow attack in v8-M TrustZone based processors. An attacker can cause a change to the stack pointer used by the Secure World from a non-secure app...
Arm Armv8-m Firmware
4.7
CVSSv3
CVE-2019-18222
The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS up to and including 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local malicious user to recover the private key via side-channel attacks.
Arm Mbed Tls
Arm Mbed Crypto
Fedoraproject Fedora 30
Fedoraproject Fedora 31
Debian Debian Linux 10.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
firmware
CVE-2023-52866
CVE-2024-4367
CVE-2024-1721
CVE-2023-34992
XML injection
CVE-2023-52817
SQL
CVE-2023-52855
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »