İçeriğe atla
Noroxi

st kayıtları

st üreticisine ait 29 yayımlanmış kayıt.

Tüm kayıtlar

29 kayıt
  • CVE-2019-14236
    40Planlayın

    On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a soft

    KritikCVSS 9,8İstismar yokEPSS %2

    st · stm32l0 firmware12 Eyl 2019

  • CVE-2024-45064
    39İzleyin

    A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    KritikCVSS 9,8İstismar yokEPSS %1

    st · x-cube-azrt-h7rs2 Nis 2025

  • CVE-2021-42553
    39İzleyin

    STM32 USB Host Library Buffer Overflow

    KritikCVSS 9,8İstismar yokEPSS %1

    st · stm32 mw usb host21 Eki 2022

  • CVE-2020-8004
    31İzleyin

    STMicroelectronics STM32F1 devices have Incorrect Access Control.

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    st · stm32f1 firmware6 Nis 2020

  • CVE-2024-50385
    30İzleyin

    A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    YüksekCVSS 7,5İstismar yokEPSS %1

    st · x-cube-azrt-h7rs2 Nis 2025

  • CVE-2024-50384
    30İzleyin

    A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    YüksekCVSS 7,5İstismar yokEPSS %1

    st · x-cube-azrt-h7rs2 Nis 2025

  • CVE-2024-50595
    30İzleyin

    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    YüksekCVSS 7,5İstismar yokEPSS %1

    st · x-cube-azrt-h7rs2 Nis 2025

  • CVE-2024-50597
    30İzleyin

    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    YüksekCVSS 7,5İstismar yokEPSS %1

    st · x-cube-azrt-h7rs2 Nis 2025

  • CVE-2024-50596
    30İzleyin

    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    YüksekCVSS 7,5İstismar yokEPSS %1

    st · x-cube-azrt-h7rs2 Nis 2025

  • CVE-2024-50594
    30İzleyin

    An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.

    YüksekCVSS 7,5İstismar yokEPSS %1

    st · x-cube-azrt-h7rs2 Nis 2025

  • CVE-2023-50096
    30İzleyin

    STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to t

    YüksekCVSS 7,5İstismar yokEPSS %1

    st · x-cube-safea11 Oca 2024

  • CVE-2020-27212
    28İzleyin

    STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control.

    YüksekCVSS 7,0İstismar yokEPSS %0

    st · stm32cubel4 firmware21 May 2021

  • CVE-2021-34262
    27İzleyin

    A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attack

    OrtaCVSS 6,8İstismar yokEPSS %0

    st · stm32cube middleware22 Tem 2021

  • CVE-2021-34259
    27İzleyin

    A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attac

    OrtaCVSS 6,8İstismar yokEPSS %0

    st · stm32cube middleware22 Tem 2021

  • CVE-2021-34260
    27İzleyin

    A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows

    OrtaCVSS 6,8İstismar yokEPSS %0

    st · stm32cube middleware22 Tem 2021

  • CVE-2020-13466
    27İzleyin

    STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific

    OrtaCVSS 6,8İstismar yokEPSS %0

    st · stm32f103 firmware31 Ağu 2020

  • CVE-2019-19192
    26İzleyin

    The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecu

    OrtaCVSS 6,5İstismar yokEPSS %1

    st · wb5512 Şub 2020

  • CVE-2019-14238
    26İzleyin

    On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a

    OrtaCVSS 6,6İstismar yokEPSS %0

    st · stm32l0 firmware24 Eyl 2019

  • CVE-2003-0392
    25İzleyin

    Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS dr

    OrtaCVSS 6,4İstismar yokEPSS %1

    st · ftp service2 Tem 2003

  • CVE-2019-16863
    24İzleyin

    STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing at

    OrtaCVSS 5,9İstismar yokEPSS %3

    st · st33tphf2espi firmware13 Kas 2019

  • CVE-2021-29414
    24İzleyin

    STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.

    OrtaCVSS 6,1İstismar yokEPSS %0

    st · stm32cubel4 firmware21 May 2021

  • CVE-2021-43392
    24İzleyin

    STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets.

    OrtaCVSS 6,2İstismar yokEPSS %0

    st · j-safe3 firmware4 Mar 2022

  • CVE-2021-43393
    24İzleyin

    STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification.

    OrtaCVSS 6,2İstismar yokEPSS %0

    st · stsafe-j firmware4 Mar 2022

  • CVE-2020-20949
    23İzleyin

    Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924).

    OrtaCVSS 5,9İstismar yokEPSS %1

    st · stm32cubef020 Oca 2021

  • CVE-2023-36629
    22İzleyin

    The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.

    OrtaCVSS 5,5İstismar yokEPSS %0

    st · st54-android-packages-apps-nfc8 Oca 2024