Vulnerabilities > NXP > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-17 CVE-2023-39902 Improper Preservation of Permissions vulnerability in NXP Uboot Secondary Program Loader
A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors.
local
low complexity
nxp CWE-281
7.8
2022-05-03 CVE-2021-22680 Integer Overflow or Wraparound vulnerability in NXP MQX 5.1
NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions.
network
low complexity
nxp CWE-190
7.5
2022-05-03 CVE-2021-27421 Integer Overflow or Wraparound vulnerability in NXP Mcuxpresso Software Development KIT 2.2.1/2.7.0
NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specified array, leading to unexpected behavior such segmentation fault when assigning a particular block of memory from the heap via malloc.
network
low complexity
nxp CWE-190
7.5
2020-02-12 CVE-2019-17519 Classic Buffer Overflow vulnerability in NXP Mcuxpresso Software Development KIT 2.2.1
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.
low complexity
nxp CWE-120
8.8
2019-09-12 CVE-2019-14237 Incorrect Authorization vulnerability in NXP products
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by observing CPU registers and the effect of code/instruction execution.
network
low complexity
nxp CWE-863
7.5