Skip to main content

Vendor archive

arm CVEs

Beta · best-effort

157 CVEs tagged to vendor arm20 Critical, 73 High, 56 Medium, 8 Low, 0 Unrated.

CVE-2025-27810

Published Mar 25, 2025

Mbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware errors, uses uninitialized stack memory to compose the TLS Finished message, po…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-27809

Published Mar 25, 2025

Mbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted certificates for arbitrary hostnames unless the TLS client application calls mb…

CVSS 5.4 · Medium
evidence mentions
4
Buzz score
31.1
Vendor/product tagsBeta · best-effort

CVE-2024-7881

Published Jan 28, 2025

An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also de…

CVSS 5.1 · Medium

CVE-2024-11864

Published Jan 14, 2025

Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11863

Published Jan 14, 2025

Specifically crafted SCMI messages sent to an SCP running SCP-Firmware release versions up to and including 2.15.0 may lead to a Usage Fault and crash the SCP

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48986

Published Nov 20, 2024

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. Certain events caus…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48984

Published Nov 20, 2024

An issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the length of a list of reports by reading a byte from an inpu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-48982

Published Nov 20, 2024

An issue was discovered in MBed OS 6.16.0. Its hci parsing software dynamically determines the length of certain hci packets by reading a byte from its header. This value is assum…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48985

Published Nov 20, 2024

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading 2 bytes from the packet d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48983

Published Nov 20, 2024

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet data by reading 2 bytes from the packet h…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-48981

Published Nov 20, 2024

An issue was discovered in MBed OS 6.16.0. During processing of HCI packets, the software dynamically determines the length of the packet header by looking up the identifying firs…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9413

Published Nov 13, 2024

The transport_message_handler function in SCP-Firmware release versions 2.11.0-2.15.0 does not properly handle errors, potentially allowing an Application Processor (AP) to cause…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1395

Published May 3, 2024

Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the sys…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 157 CVEsPage 2 of 7