Skip to main content

Vendor archive

nxp CVEs

Beta · best-effort

20 CVEs tagged to vendor nxp1 Critical, 9 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2021-27421

Published May 3, 2022

NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow to access memory locations outside the bounds of a specifie…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22680

Published May 3, 2022

NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. This unverified memory assignment can lead to arbitrary memo…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2022-22819

Published Mar 23, 2022

NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a buffer overflow in parsing SB2 updates…

CVSS 7.8 · High

CVE-2021-44149

Published Dec 7, 2021

An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-re…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44479

Published Dec 1, 2021

NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Programming (ISP) mode. This discloses protec…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3011

Published Jan 7, 2021

An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication microcontrollers, with CryptoLib through v2.…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-20 of 20 CVEsPage 1 of 1