Arm records
165 published records for vendor arm.
Researcher profile
- Entered KEV
- 8 · 4.8%
- Weaponized
- 8 · 4.8%
- Pre-auth RCE
- 5
- With a fix record
- 57.6%
- Median publish → KEV
- 167 days
Recurring classes
- CWE-416 Use After Free39
- CWE-203 Observable Discrepancy17
- CWE-125 Out-of-bounds Read10
- CWE-190 Integer Overflow or Wraparound8
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')7
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
165 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
69This week | CVE-2022-38181Weaponized | The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled.arm · bifrost gpu kernel driver · CWE-416 | High8.8 | KEV | 13.6% | Oct 25, 2022 |
69This week | CVE-2021-28663Weaponized | The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading tarm · bifrost gpu kernel driver · CWE-416 | High8.8 | KEV | 12.1% | May 10, 2021 |
67This week | CVE-2021-28664Weaponized | The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achiearm · bifrost gpu kernel driver · CWE-787 | High8.8 | KEV | 5.4% | May 10, 2021 |
66This week | CVE-2021-29256Weaponized | .arm · bifrost gpu kernel driver · CWE-416 | High8.8 | KEV | 3.0% | May 24, 2021 |
61This week | CVE-2022-22706Weaponized | Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages.arm · bifrost gpu kernel driver · CWE-119 | High7.8 | KEV | 1.1% | Mar 3, 2022 |
61This week | CVE-2024-4610Weaponized | Mali GPU Kernel Driver allows improper GPU memory processing operationsarm · bifrost gpu kernel driver · CWE-416 | High7.8 | KEV | 0.8% | Jun 7, 2024 |
52Plan | CVE-2023-4211Weaponized | Mali GPU Kernel Driver Allows Improper GPU Memory Processing Operationsarm · 5th gen gpu architecture kernel driver · CWE-416 | Medium5.5 | KEV | 1.1% | Oct 1, 2023 |
50Plan | CVE-2017-5753Proof of concept | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an atintel · atom c · CWE-203 | Medium5.6 | — | 93.8% | Jan 4, 2018 |
47Plan | CVE-2017-5754Proof of concept | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of informationintel · atom c · CWE-200 | Medium5.6 | — | 84.2% | Jan 4, 2018 |
44Plan | CVE-2017-5715Proof of concept | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of informationintel · atom c · CWE-203 | Medium5.6 | — | 74.0% | Jan 4, 2018 |
43Plan | CVE-2023-26083Weaponized | Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver aarm · 5th gen gpu architecture kernel driver · CWE-401 | Low3.3 | KEV | 1.2% | Apr 6, 2023 |
40Plan | CVE-2018-3639Proof of concept | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Medium5.5 | — | 60.6% | May 22, 2018 |
40Plan | CVE-2018-0488No exploit | ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to arm · mbed tls · CWE-787 | Critical9.8 | — | 4.8% | Feb 13, 2018 |
40Plan | CVE-2018-0487No exploit | ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (arm · mbed tls · CWE-119 | Critical9.8 | — | 3.3% | Feb 13, 2018 |
40Plan | CVE-2017-18187No exploit | In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_pskarm · mbed tls · CWE-190 | Critical9.8 | — | 3.1% | Feb 14, 2018 |
40Plan | CVE-2021-44732No exploit | Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.arm · mbed tls · CWE-415 | Critical9.8 | — | 2.6% | Dec 20, 2021 |
40Plan | CVE-2025-47917Proof of concept | Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation.arm · mbed tls · CWE-416 | Critical9.8 | — | 2.1% | Jul 20, 2025 |
40Plan | CVE-2021-27435No exploit | ARM mbed Integer Overflow or Wraparoundarm · mbed · CWE-190 | Critical9.8 | — | 1.9% | May 3, 2022 |
40Plan | CVE-2021-27433No exploit | ARM mbed-ualloc memory library Integer Overflow or Wraparoundarm · mbed ualloc · CWE-190 | Critical9.8 | — | 1.8% | May 3, 2022 |
39Monitor | CVE-2022-28348No exploit | Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37parm · bifrost gpu kernel driver · CWE-416 | Critical9.8 | — | 1.4% | May 18, 2022 |
39Monitor | CVE-2022-28350No exploit | Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-after-free situation.arm · valhall gpu kernel driver · CWE-416 | Critical9.8 | — | 1.4% | May 18, 2022 |
39Monitor | CVE-2022-28349No exploit | Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Valarm · bifrost gpu kernel driver · CWE-416 | Critical9.8 | — | 1.2% | May 18, 2022 |
39Monitor | CVE-2021-43086No exploit | ARM astcenc 3.2.0 is vulnerable to Buffer Overflow.arm · adaptive scalable texture compression encoder · CWE-787 | Critical9.8 | — | 1.2% | Feb 28, 2022 |
39Monitor | CVE-2022-46393No exploit | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0.arm · mbed tls · CWE-125 | Critical9.8 | — | 1.2% | Dec 15, 2022 |
39Monitor | CVE-2021-27431No exploit | ARM CMSIS RTOS2 Integer Overflow or Wraparoundarm · cmsis-rtos · CWE-190 | Critical9.8 | — | 1.1% | May 3, 2022 |
- CVE-2022-3818169This week
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled.
HighCVSS 8.8KEVWeaponizedEPSS 14%arm · bifrost gpu kernel driverOct 25, 2022
- CVE-2021-2866369This week
The Arm Mali GPU kernel driver allows privilege escalation or information disclosure because GPU memory operations are mishandled, leading t
HighCVSS 8.8KEVWeaponizedEPSS 12%arm · bifrost gpu kernel driverMay 10, 2021
- CVE-2021-2866467This week
The Arm Mali GPU kernel driver allows privilege escalation or a denial of service (memory corruption) because an unprivileged user can achie
HighCVSS 8.8KEVWeaponizedEPSS 5%arm · bifrost gpu kernel driverMay 10, 2021
- CVE-2021-2925666This week
.
HighCVSS 8.8KEVWeaponizedEPSS 3%arm · bifrost gpu kernel driverMay 24, 2021
- CVE-2022-2270661This week
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages.
HighCVSS 7.8KEVWeaponizedEPSS 1%arm · bifrost gpu kernel driverMar 3, 2022
- CVE-2024-461061This week
Mali GPU Kernel Driver allows improper GPU memory processing operations
HighCVSS 7.8KEVWeaponizedEPSS 1%arm · bifrost gpu kernel driverJun 7, 2024
- CVE-2023-421152Plan
Mali GPU Kernel Driver Allows Improper GPU Memory Processing Operations
MediumCVSS 5.5KEVWeaponizedEPSS 1%arm · 5th gen gpu architecture kernel driverOct 1, 2023
- CVE-2017-575350Plan
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an at
MediumCVSS 5.6Proof of conceptEPSS 94%intel · atom cJan 4, 2018
- CVE-2017-575447Plan
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information
MediumCVSS 5.6Proof of conceptEPSS 84%intel · atom cJan 4, 2018
- CVE-2017-571544Plan
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information
MediumCVSS 5.6Proof of conceptEPSS 74%intel · atom cJan 4, 2018
- CVE-2023-2608343Plan
Memory leak vulnerability in Mali GPU Kernel Driver in Midgard GPU Kernel Driver all versions from r6p0 - r32p0, Bifrost GPU Kernel Driver a
LowCVSS 3.3KEVWeaponizedEPSS 1%arm · 5th gen gpu architecture kernel driverApr 6, 2023
- CVE-2018-363940Plan
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
MediumCVSS 5.5Proof of conceptEPSS 61%intel · atom cMay 22, 2018
- CVE-2018-048840Plan
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to
CriticalCVSS 9.8No exploitEPSS 5%arm · mbed tlsFeb 13, 2018
- CVE-2018-048740Plan
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (
CriticalCVSS 9.8No exploitEPSS 3%arm · mbed tlsFeb 13, 2018
- CVE-2017-1818740Plan
In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk
CriticalCVSS 9.8No exploitEPSS 3%arm · mbed tlsFeb 14, 2018
- CVE-2021-4473240Plan
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
CriticalCVSS 9.8No exploitEPSS 3%arm · mbed tlsDec 20, 2021
- CVE-2025-4791740Plan
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance with the documentation.
CriticalCVSS 9.8Proof of conceptEPSS 2%arm · mbed tlsJul 20, 2025
- CVE-2021-2743540Plan
ARM mbed Integer Overflow or Wraparound
CriticalCVSS 9.8No exploitEPSS 2%arm · mbedMay 3, 2022
- CVE-2021-2743340Plan
ARM mbed-ualloc memory library Integer Overflow or Wraparound
CriticalCVSS 9.8No exploitEPSS 2%arm · mbed uallocMay 3, 2022
- CVE-2022-2834839Monitor
Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifrost r0p0 through r36p0 before r37p0, and Valhall r19p0 through r36p0 before r37p
CriticalCVSS 9.8No exploitEPSS 1%arm · bifrost gpu kernel driverMay 18, 2022
- CVE-2022-2835039Monitor
Arm Mali GPU Kernel Driver allows improper GPU operations in Valhall r29p0 through r36p0 before r37p0 to reach a use-after-free situation.
CriticalCVSS 9.8No exploitEPSS 1%arm · valhall gpu kernel driverMay 18, 2022
- CVE-2022-2834939Monitor
Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28p0 through r29p0 before r30p0, Bifrost r17p0 through r23p0 before r24p0, and Val
CriticalCVSS 9.8No exploitEPSS 1%arm · bifrost gpu kernel driverMay 18, 2022
- CVE-2021-4308639Monitor
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow.
CriticalCVSS 9.8No exploitEPSS 1%arm · adaptive scalable texture compression encoderFeb 28, 2022
- CVE-2022-4639339Monitor
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0.
CriticalCVSS 9.8No exploitEPSS 1%arm · mbed tlsDec 15, 2022
- CVE-2021-2743139Monitor
ARM CMSIS RTOS2 Integer Overflow or Wraparound
CriticalCVSS 9.8No exploitEPSS 1%arm · cmsis-rtosMay 3, 2022