Vulnerabilities > ARM
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-07 | CVE-2023-3889 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in ARM Valhall GPU Kernel Driver A local non-privileged user can make improper GPU memory processing operations. | 7.8 |
2023-11-07 | CVE-2023-4272 | Unspecified vulnerability in ARM products A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory. | 5.5 |
2023-11-07 | CVE-2023-4295 | Use After Free vulnerability in ARM Mali GPU Kernel Driver and Valhall GPU Kernel Driver A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | 7.8 |
2023-10-07 | CVE-2023-43615 | Classic Buffer Overflow vulnerability in multiple products Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow. | 7.5 |
2023-10-07 | CVE-2023-45199 | Classic Buffer Overflow vulnerability in ARM Mbed TLS 3.2.0/3.3.0 Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution. | 9.8 |
2023-10-03 | CVE-2023-33200 | Use After Free vulnerability in ARM products A local non-privileged user can make improper GPU processing operations to exploit a software race condition. | 4.7 |
2023-10-03 | CVE-2023-34970 | Out-of-bounds Write vulnerability in ARM Mali GPU Kernel Driver and Valhall GPU Kernel Driver A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition. | 4.7 |
2023-10-01 | CVE-2023-4211 | Use After Free vulnerability in ARM products A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | 5.5 |
2023-09-08 | CVE-2023-40271 | Incorrect Comparison vulnerability in ARM Trusted Firmware-M In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the build-time configuration phase) implemented with a dedicated function (i.e., not relying on usage of multipart functions), the buffer comparison during the verification of the authentication tag does not happen on the full 16 bytes but just on the first 4 bytes, thus leading to the possibility that unauthenticated payloads might be identified as authentic. | 7.5 |
2023-07-27 | CVE-2022-43701 | Incorrect Default Permissions vulnerability in ARM products When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code. | 7.8 |