Vulnerabilities > ARM

DATE CVE VULNERABILITY TITLE RISK
2023-12-04 CVE-2023-32804 Out-of-bounds Write vulnerability in ARM products
Out-of-bounds Write vulnerability in Arm Ltd Midgard GPU Userspace Driver, Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a local non-privileged user to write a constant pattern to a limited amount of memory not allocated by the user space driver.This issue affects Midgard GPU Userspace Driver: from r0p0 through r32p0; Bifrost GPU Userspace Driver: from r0p0 through r44p0; Valhall GPU Userspace Driver: from r19p0 through r44p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r44p0.
local
low complexity
arm CWE-787
7.8
2023-12-01 CVE-2023-5427 Use After Free vulnerability in ARM products
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r44p0 through r45p0; Valhall GPU Kernel Driver: from r44p0 through r45p0; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r45p0.
local
low complexity
arm CWE-416
7.8
2023-11-07 CVE-2023-3889 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in ARM Valhall GPU Kernel Driver
A local non-privileged user can make improper GPU memory processing operations.
local
low complexity
arm CWE-119
7.8
2023-11-07 CVE-2023-4272 Unspecified vulnerability in ARM products
A local non-privileged user can make GPU processing operations that expose sensitive data from previously freed memory.
local
low complexity
arm
5.5
2023-11-07 CVE-2023-4295 Use After Free vulnerability in ARM Mali GPU Kernel Driver and Valhall GPU Kernel Driver
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
local
low complexity
arm CWE-416
7.8
2023-10-07 CVE-2023-43615 Classic Buffer Overflow vulnerability in multiple products
Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
network
low complexity
arm fedoraproject CWE-120
7.5
2023-10-07 CVE-2023-45199 Classic Buffer Overflow vulnerability in ARM Mbed TLS 3.2.0/3.3.0
Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
network
low complexity
arm CWE-120
critical
9.8
2023-10-03 CVE-2023-33200 Use After Free vulnerability in ARM products
A local non-privileged user can make improper GPU processing operations to exploit a software race condition.
local
high complexity
arm CWE-416
4.7
2023-10-03 CVE-2023-34970 Out-of-bounds Write vulnerability in ARM Mali GPU Kernel Driver and Valhall GPU Kernel Driver
A local non-privileged user can make improper GPU processing operations to access a limited amount outside of buffer bounds or to exploit a software race condition.
local
high complexity
arm CWE-787
4.7
2023-10-01 CVE-2023-4211 Use After Free vulnerability in ARM products
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
local
low complexity
arm CWE-416
5.5