Vulnerabilities > ARM > High

DATE CVE VULNERABILITY TITLE RISK
2021-08-23 CVE-2020-36476 Improper Cross-boundary Removal of Sensitive Data vulnerability in multiple products
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS).
network
low complexity
arm debian CWE-212
7.5
2021-08-23 CVE-2020-36478 Improper Certificate Validation vulnerability in multiple products
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS).
network
low complexity
arm siemens debian CWE-295
7.5
2021-07-19 CVE-2020-36423 Cleartext Transmission of Sensitive Information vulnerability in multiple products
An issue was discovered in Arm Mbed TLS before 2.23.0.
network
low complexity
arm debian CWE-319
7.5
2021-07-19 CVE-2020-36426 Out-of-bounds Read vulnerability in multiple products
An issue was discovered in Arm Mbed TLS before 2.24.0.
network
low complexity
arm debian CWE-125
7.5
2021-05-24 CVE-2021-29256 Use After Free vulnerability in ARM Bifrost, Midgard and Valhall
.
network
low complexity
arm CWE-416
8.8
2021-05-10 CVE-2021-28663 Use After Free vulnerability in ARM products
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading to a use-after-free.
network
low complexity
arm CWE-416
8.8
2021-05-10 CVE-2021-28664 Out-of-bounds Write vulnerability in ARM products
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achieve read/write access to read-only pages.
network
low complexity
arm CWE-787
8.8
2020-12-24 CVE-2020-24658 Allocation of Resources Without Limits or Throttling vulnerability in ARM Compiler
Arm Compiler 5 through 5.06u6 has an error in a stack protection feature designed to help spot stack-based buffer overflows in local arrays.
local
low complexity
arm CWE-770
7.8
2020-11-12 CVE-2020-16273 Integer Underflow (Wrap or Wraparound) vulnerability in ARM Armv8-M Firmware
In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by a stack-underflow attack in v8-M TrustZone based processors.
local
low complexity
arm CWE-191
7.8
2020-06-18 CVE-2020-12887 Memory Leak vulnerability in ARM Mbed-Coap 5.1.5
Memory leaks were discovered in the CoAP library in Arm Mbed OS 5.15.3 when using the Arm mbed-coap library 5.1.5.
network
low complexity
arm CWE-401
7.5