Vulnerabilities > Microchip

DATE CVE VULNERABILITY TITLE RISK
2020-02-17 CVE-2020-9034 Improper Input Validation vulnerability in Microchip products
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users.
network
low complexity
microchip CWE-20
5.0
2020-02-10 CVE-2019-19195 Unspecified vulnerability in Microchip Atmsamb11 Blusdk Smart 6.2
The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer data length on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
low complexity
microchip
6.1
2019-10-03 CVE-2019-15809 Information Exposure Through Discrepancy vulnerability in multiple products
Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation.
1.2
2009-05-18 CVE-2009-1674 Buffer Errors vulnerability in Microchip Mplab IDE 8.30
Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CVE-2009-1608.
network
microchip CWE-119
critical
9.3
2009-05-11 CVE-2009-1608 Buffer Errors vulnerability in Microchip Mplab IDE 8.30
Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers to execute arbitrary code via a .MCP project file with long (1) FILE_INFO, (2) CAT_FILTERS, and possibly other fields.
network
microchip CWE-119
critical
9.3