Vulnerabilities > ARM > Mbed TLS > 2.7.17
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-20 | CVE-2021-44732 | Double Free vulnerability in multiple products Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. | 9.8 |
2021-08-23 | CVE-2020-36475 | Incorrect Calculation of Buffer Size vulnerability in multiple products An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). | 7.5 |
2021-08-23 | CVE-2020-36477 | Improper Certificate Validation vulnerability in ARM Mbed TLS An issue was discovered in Mbed TLS before 2.24.0. | 5.9 |
2021-08-23 | CVE-2020-36478 | Improper Certificate Validation vulnerability in multiple products An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). | 7.5 |
2021-07-19 | CVE-2020-36421 | Information Exposure Through Discrepancy vulnerability in multiple products An issue was discovered in Arm Mbed TLS before 2.23.0. | 5.3 |
2021-07-19 | CVE-2020-36422 | Information Exposure Through Discrepancy vulnerability in multiple products An issue was discovered in Arm Mbed TLS before 2.23.0. | 5.3 |
2021-07-19 | CVE-2020-36423 | Cleartext Transmission of Sensitive Information vulnerability in multiple products An issue was discovered in Arm Mbed TLS before 2.23.0. | 7.5 |
2021-07-14 | CVE-2021-24119 | Information Exposure Through Discrepancy vulnerability in multiple products In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX. | 4.9 |
2020-03-24 | CVE-2020-10941 | Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import. | 5.9 |