st kayıtları
st üreticisine ait 29 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-191 Integer Underflow (Wrap or Wraparound)4
- CWE-347 Improper Verification of Cryptographic Signature2
- CWE-459 Incomplete Cleanup2
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
29 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-14236İstismar yok | On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a softst · stm32l0 firmware · CWE-863 | Kritik9,8 | — | %2,3 | 12 Eyl 2019 |
39İzleyin | CVE-2024-45064İstismar yok | A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-119 | Kritik9,8 | — | %1,1 | 2 Nis 2025 |
39İzleyin | CVE-2021-42553İstismar yok | STM32 USB Host Library Buffer Overflowst · stm32 mw usb host · CWE-120 | Kritik9,8 | — | %1,1 | 21 Eki 2022 |
31İzleyin | CVE-2020-8004Kavram kanıtı | STMicroelectronics STM32F1 devices have Incorrect Access Control.st · stm32f1 firmware | Yüksek7,5 | — | %3,0 | 6 Nis 2020 |
30İzleyin | CVE-2024-50385İstismar yok | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-459 | Yüksek7,5 | — | %0,8 | 2 Nis 2025 |
30İzleyin | CVE-2024-50384İstismar yok | A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-459 | Yüksek7,5 | — | %0,8 | 2 Nis 2025 |
30İzleyin | CVE-2024-50595İstismar yok | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-191 | Yüksek7,5 | — | %0,8 | 2 Nis 2025 |
30İzleyin | CVE-2024-50597İstismar yok | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-191 | Yüksek7,5 | — | %0,8 | 2 Nis 2025 |
30İzleyin | CVE-2024-50596İstismar yok | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-191 | Yüksek7,5 | — | %0,8 | 2 Nis 2025 |
30İzleyin | CVE-2024-50594İstismar yok | An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.st · x-cube-azrt-h7rs · CWE-191 | Yüksek7,5 | — | %0,8 | 2 Nis 2025 |
30İzleyin | CVE-2023-50096İstismar yok | STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to tst · x-cube-safea1 · CWE-120 | Yüksek7,5 | — | %0,6 | 1 Oca 2024 |
28İzleyin | CVE-2020-27212İstismar yok | STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control.st · stm32cubel4 firmware · CWE-74 | Yüksek7,0 | — | %0,3 | 21 May 2021 |
27İzleyin | CVE-2021-34262İstismar yok | A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attackst · stm32cube middleware · CWE-120 | Orta6,8 | — | %0,5 | 22 Tem 2021 |
27İzleyin | CVE-2021-34259İstismar yok | A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attacst · stm32cube middleware · CWE-120 | Orta6,8 | — | %0,5 | 22 Tem 2021 |
27İzleyin | CVE-2021-34260İstismar yok | A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allowsst · stm32cube middleware · CWE-120 | Orta6,8 | — | %0,5 | 22 Tem 2021 |
27İzleyin | CVE-2020-13466İstismar yok | STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specificst · stm32f103 firmware | Orta6,8 | — | %0,4 | 31 Ağu 2020 |
26İzleyin | CVE-2019-19192İstismar yok | The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecust · wb55 · CWE-20 | Orta6,5 | — | %1,0 | 12 Şub 2020 |
26İzleyin | CVE-2019-14238İstismar yok | On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with ast · stm32l0 firmware · CWE-287 | Orta6,6 | — | %0,4 | 24 Eyl 2019 |
25İzleyin | CVE-2003-0392İstismar yok | Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS drst · ftp service | Orta6,4 | — | %1,4 | 2 Tem 2003 |
24İzleyin | CVE-2019-16863İstismar yok | STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing atst · st33tphf2espi firmware · CWE-203 | Orta5,9 | — | %3,4 | 13 Kas 2019 |
24İzleyin | CVE-2021-29414İstismar yok | STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.st · stm32cubel4 firmware · CWE-74 | Orta6,1 | — | %0,3 | 21 May 2021 |
24İzleyin | CVE-2021-43392İstismar yok | STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets.st · j-safe3 firmware · CWE-347 | Orta6,2 | — | %0,2 | 4 Mar 2022 |
24İzleyin | CVE-2021-43393İstismar yok | STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification.st · stsafe-j firmware · CWE-347 | Orta6,2 | — | %0,2 | 4 Mar 2022 |
23İzleyin | CVE-2020-20949İstismar yok | Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924).st · stm32cubef0 · CWE-327 | Orta5,9 | — | %0,9 | 20 Oca 2021 |
22İzleyin | CVE-2023-36629İstismar yok | The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.st · st54-android-packages-apps-nfc · CWE-125 | Orta5,5 | — | %0,4 | 8 Oca 2024 |
- CVE-2019-1423640Planlayın
On STMicroelectronics STM32L0, STM32L1, STM32L4, STM32F4, STM32F7, and STM32H7 devices, Proprietary Code Read Out Protection (PCROP) (a soft
KritikCVSS 9,8İstismar yokEPSS %2st · stm32l0 firmware12 Eyl 2019
- CVE-2024-4506439İzleyin
A buffer overflow vulnerability exists in the FileX Internal RAM interface functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
KritikCVSS 9,8İstismar yokEPSS %1st · x-cube-azrt-h7rs2 Nis 2025
- CVE-2021-4255339İzleyin
STM32 USB Host Library Buffer Overflow
KritikCVSS 9,8İstismar yokEPSS %1st · stm32 mw usb host21 Eki 2022
- CVE-2020-800431İzleyin
STMicroelectronics STM32F1 devices have Incorrect Access Control.
YüksekCVSS 7,5Kavram kanıtıEPSS %3st · stm32f1 firmware6 Nis 2020
- CVE-2024-5038530İzleyin
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
YüksekCVSS 7,5İstismar yokEPSS %1st · x-cube-azrt-h7rs2 Nis 2025
- CVE-2024-5038430İzleyin
A denial of service vulnerability exists in the NetX Component HTTP server functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
YüksekCVSS 7,5İstismar yokEPSS %1st · x-cube-azrt-h7rs2 Nis 2025
- CVE-2024-5059530İzleyin
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
YüksekCVSS 7,5İstismar yokEPSS %1st · x-cube-azrt-h7rs2 Nis 2025
- CVE-2024-5059730İzleyin
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
YüksekCVSS 7,5İstismar yokEPSS %1st · x-cube-azrt-h7rs2 Nis 2025
- CVE-2024-5059630İzleyin
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
YüksekCVSS 7,5İstismar yokEPSS %1st · x-cube-azrt-h7rs2 Nis 2025
- CVE-2024-5059430İzleyin
An integer underflow vulnerability exists in the HTTP server PUT request functionality of STMicroelectronics X-CUBE-AZRTOS-WL 2.0.0.
YüksekCVSS 7,5İstismar yokEPSS %1st · x-cube-azrt-h7rs2 Nis 2025
- CVE-2023-5009630İzleyin
STMicroelectronics STSAFE-A1xx middleware before 3.3.7 allows MCU code execution if an adversary has the ability to read from and write to t
YüksekCVSS 7,5İstismar yokEPSS %1st · x-cube-safea11 Oca 2024
- CVE-2020-2721228İzleyin
STMicroelectronics STM32L4 devices through 2020-10-19 have incorrect access control.
YüksekCVSS 7,0İstismar yokEPSS %0st · stm32cubel4 firmware21 May 2021
- CVE-2021-3426227İzleyin
A buffer overflow vulnerability in the USBH_ParseEPDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attack
OrtaCVSS 6,8İstismar yokEPSS %0st · stm32cube middleware22 Tem 2021
- CVE-2021-3425927İzleyin
A buffer overflow vulnerability in the USBH_ParseCfgDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows attac
OrtaCVSS 6,8İstismar yokEPSS %0st · stm32cube middleware22 Tem 2021
- CVE-2021-3426027İzleyin
A buffer overflow vulnerability in the USBH_ParseInterfaceDesc() function of STMicroelectronics STM32Cube Middleware v1.8.0 and below allows
OrtaCVSS 6,8İstismar yokEPSS %0st · stm32cube middleware22 Tem 2021
- CVE-2020-1346627İzleyin
STMicroelectronics STM32F103 devices through 2020-05-20 allow physical attackers to execute arbitrary code via a power glitch and a specific
OrtaCVSS 6,8İstismar yokEPSS %0st · stm32f103 firmware31 Ağu 2020
- CVE-2019-1919226İzleyin
The Bluetooth Low Energy implementation on STMicroelectronics BLE Stack through 1.3.1 for STM32WB5x devices does not properly handle consecu
OrtaCVSS 6,5İstismar yokEPSS %1st · wb5512 Şub 2020
- CVE-2019-1423826İzleyin
On STMicroelectronics STM32F7 devices, Proprietary Code Read Out Protection (PCROP) (a software IP protection method) can be defeated with a
OrtaCVSS 6,6İstismar yokEPSS %0st · stm32l0 firmware24 Eyl 2019
- CVE-2003-039225İzleyin
Directory traversal vulnerability in ST FTP Service 3.0 allows remote attackers to list arbitrary directories via a CD command with a DoS dr
OrtaCVSS 6,4İstismar yokEPSS %1st · ftp service2 Tem 2003
- CVE-2019-1686324İzleyin
STMicroelectronics ST33TPHF2ESPI TPM devices before 2019-09-12 allow attackers to extract the ECDSA private key via a side-channel timing at
OrtaCVSS 5,9İstismar yokEPSS %3st · st33tphf2espi firmware13 Kas 2019
- CVE-2021-2941424İzleyin
STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.
OrtaCVSS 6,1İstismar yokEPSS %0st · stm32cubel4 firmware21 May 2021
- CVE-2021-4339224İzleyin
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptographic secrets.
OrtaCVSS 6,2İstismar yokEPSS %0st · j-safe3 firmware4 Mar 2022
- CVE-2021-4339324İzleyin
STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification.
OrtaCVSS 6,2İstismar yokEPSS %0st · stsafe-j firmware4 Mar 2022
- CVE-2020-2094923İzleyin
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924).
OrtaCVSS 5,9İstismar yokEPSS %1st · stm32cubef020 Oca 2021
- CVE-2023-3662922İzleyin
The ST ST54-android-packages-apps-Nfc package before 130-20230215-23W07p0 for Android has an out-of-bounds read.
OrtaCVSS 5,5İstismar yokEPSS %0st · st54-android-packages-apps-nfc8 Oca 2024