Vulnerabilities > ARM

DATE CVE VULNERABILITY TITLE RISK
2023-09-08 CVE-2023-40271 Incorrect Comparison vulnerability in ARM Trusted Firmware-M
In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the build-time configuration phase) implemented with a dedicated function (i.e., not relying on usage of multipart functions), the buffer comparison during the verification of the authentication tag does not happen on the full 16 bytes but just on the first 4 bytes, thus leading to the possibility that unauthenticated payloads might be identified as authentic.
network
low complexity
arm CWE-697
7.5
2023-07-27 CVE-2022-43701 Incorrect Default Permissions vulnerability in ARM products
When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.
local
low complexity
arm CWE-276
7.8
2023-07-27 CVE-2022-43702 Incorrect Default Permissions vulnerability in ARM products
When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.
local
low complexity
arm CWE-276
7.8
2023-07-27 CVE-2022-43703 Uncontrolled Search Path Element vulnerability in ARM Development Studio and DS Development Studio
An installer that loads or executes files using an unconstrained search path may be vulnerable to substitute files under control of an attacker being loaded or executed instead of the intended files.
local
low complexity
arm CWE-427
7.8
2023-06-29 CVE-2023-26085 Out-of-bounds Write vulnerability in ARM NN Android Neural Networks Driver
A possible out-of-bounds read and write (due to an improper length check of shared memory) was discovered in Arm NN Android-NN-Driver before 23.02.
local
low complexity
arm CWE-787
7.8
2023-06-02 CVE-2023-28469 Unspecified vulnerability in ARM products
An issue was discovered in the Arm Mali GPU Kernel Driver.
local
low complexity
arm
5.5
2023-06-02 CVE-2023-28147 Unspecified vulnerability in ARM products
An issue was discovered in the Arm Mali GPU Kernel Driver.
local
low complexity
arm
5.5
2023-04-11 CVE-2022-46396 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in ARM products
An issue was discovered in the Arm Mali Kernel Driver.
local
low complexity
arm CWE-119
3.3
2023-04-11 CVE-2023-22808 Out-of-bounds Read vulnerability in ARM products
An issue was discovered in the Arm Android Gralloc Module.
local
low complexity
arm CWE-125
3.3
2023-04-06 CVE-2022-46781 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in ARM products
An issue was discovered in the Arm Mali GPU Kernel Driver.
local
low complexity
arm CWE-119
3.3