Vulnerabilities > ARM

DATE CVE VULNERABILITY TITLE RISK
2023-01-16 CVE-2022-47630 Out-of-bounds Read vulnerability in ARM Trusted Firmware-A
Trusted Firmware-A through 2.8 has an out-of-bounds read in the X.509 parser for parsing boot certificates.
network
high complexity
arm CWE-125
7.4
2023-01-10 CVE-2022-48251 Information Exposure Through Discrepancy vulnerability in ARM products
The AES instructions on the ARMv8 platform do not have an algorithm that is "intrinsically resistant" to side-channel attacks.
network
low complexity
arm CWE-203
7.5
2022-12-15 CVE-2022-46392 Information Exposure Through Discrepancy vulnerability in multiple products
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0.
network
high complexity
arm fedoraproject CWE-203
5.3
2022-12-15 CVE-2022-46393 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0.
network
low complexity
arm fedoraproject CWE-787
critical
9.8
2022-12-12 CVE-2022-42716 Use After Free vulnerability in ARM Valhall GPU Kernel Driver
An issue was discovered in the Arm Mali GPU Kernel Driver.
network
low complexity
arm CWE-416
8.8
2022-11-23 CVE-2022-34830 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in ARM Utgard GPU Kernel Driver R11P0/R12P0
An Arm product family through 2022-06-29 has a TOCTOU Race Condition that allows non-privileged user to make improper GPU processing operations to gain access to already freed memory.
network
high complexity
arm CWE-367
7.5
2022-11-08 CVE-2022-41757 Unspecified vulnerability in ARM Valhall GPU Kernel Driver
An issue was discovered in the Arm Mali GPU Kernel Driver.
network
low complexity
arm
8.8
2022-10-25 CVE-2022-38181 Use After Free vulnerability in ARM products
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled.
network
low complexity
arm CWE-416
8.8
2022-09-01 CVE-2022-36449 Use After Free vulnerability in ARM Bifrost, Midgard and Valhall
An issue was discovered in the Arm Mali GPU Kernel Driver.
network
low complexity
arm CWE-416
6.5
2022-07-15 CVE-2022-35409 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0.
network
low complexity
arm debian CWE-125
critical
9.1