Vulnerabilities > NXP > Mcuxpresso Software Development KIT > 2.7.0

DATE CVE VULNERABILITY TITLE RISK
2022-05-03 CVE-2021-27421 Unspecified vulnerability in NXP Mcuxpresso Software Development KIT
NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.
network
low complexity
nxp
critical
9.8
2021-10-25 CVE-2021-38258 Classic Buffer Overflow vulnerability in NXP Mcuxpresso Software Development KIT 2.7.0
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().
local
low complexity
nxp CWE-120
7.8
2021-10-25 CVE-2021-38260 Classic Buffer Overflow vulnerability in NXP Mcuxpresso Software Development KIT 2.7.0
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor().
local
low complexity
nxp CWE-120
7.8