Vulnerabilities > ARM > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-01-31 | CVE-2024-23775 | Integer Overflow or Wraparound vulnerability in ARM Mbed TLS Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension(). | 7.5 |
2024-01-21 | CVE-2023-52353 | Session Fixation vulnerability in ARM Mbed TLS An issue was discovered in Mbed TLS through 3.5.1. | 7.5 |
2024-01-21 | CVE-2024-23744 | Unspecified vulnerability in ARM Mbed TLS 3.5.0/3.5.1 An issue was discovered in Mbed TLS 3.5.1. | 7.5 |
2023-12-04 | CVE-2023-32804 | Out-of-bounds Write vulnerability in ARM products Out-of-bounds Write vulnerability in Arm Ltd Midgard GPU Userspace Driver, Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a local non-privileged user to write a constant pattern to a limited amount of memory not allocated by the user space driver.This issue affects Midgard GPU Userspace Driver: from r0p0 through r32p0; Bifrost GPU Userspace Driver: from r0p0 through r44p0; Valhall GPU Userspace Driver: from r19p0 through r44p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r44p0. | 7.8 |
2023-12-01 | CVE-2023-5427 | Use After Free vulnerability in ARM products Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r44p0 through r45p0; Valhall GPU Kernel Driver: from r44p0 through r45p0; Arm 5th Gen GPU Architecture Kernel Driver: from r44p0 through r45p0. | 7.8 |
2023-11-07 | CVE-2023-3889 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in ARM Valhall GPU Kernel Driver A local non-privileged user can make improper GPU memory processing operations. | 7.8 |
2023-11-07 | CVE-2023-4295 | Use After Free vulnerability in ARM Mali GPU Kernel Driver and Valhall GPU Kernel Driver A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | 7.8 |
2023-10-07 | CVE-2023-43615 | Classic Buffer Overflow vulnerability in multiple products Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow. | 7.5 |
2023-09-08 | CVE-2023-40271 | Incorrect Comparison vulnerability in ARM Trusted Firmware-M In Trusted Firmware-M through TF-Mv1.8.0, for platforms that integrate the CryptoCell accelerator, when the CryptoCell PSA Driver software Interface is selected, and the Authenticated Encryption with Associated Data Chacha20-Poly1305 algorithm is used, with the single-part verification function (defined during the build-time configuration phase) implemented with a dedicated function (i.e., not relying on usage of multipart functions), the buffer comparison during the verification of the authentication tag does not happen on the full 16 bytes but just on the first 4 bytes, thus leading to the possibility that unauthenticated payloads might be identified as authentic. | 7.5 |
2023-07-27 | CVE-2022-43701 | Incorrect Default Permissions vulnerability in ARM products When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code. | 7.8 |