Vulnerabilities > ARM > Mbed TLS > 2.0.0

DATE CVE VULNERABILITY TITLE RISK
2018-04-10 CVE-2018-9988 Out-of-bounds Read vulnerability in multiple products
ARM mbed TLS before 2.1.11, before 2.7.2, and before 2.8.0 has a buffer over-read in ssl_parse_server_key_exchange() that could cause a crash on invalid input.
network
low complexity
arm debian CWE-125
7.5
2018-02-14 CVE-2017-18187 Integer Overflow or Wraparound vulnerability in multiple products
In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity() function in library/ssl_srv.c.
network
low complexity
arm debian CWE-190
critical
9.8
2017-08-30 CVE-2017-14032 Improper Authentication vulnerability in ARM Mbed TLS
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentication via an X.509 certificate chain with many intermediates.
network
high complexity
arm CWE-287
8.1
2017-04-20 CVE-2017-2784 Improper Certificate Validation vulnerability in ARM Mbed TLS
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2.
network
high complexity
arm CWE-295
8.1