Skip to content
Noroxi

NXP records

20 published records for vendor nxp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

20 records
  • On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only ac

    CriticalCVSS 9.8No exploitEPSS 3%

    nxp · kinetis kv1x firmwareSep 12, 2019

  • NXP MQX Integer Overflow or Wraparound

    CriticalCVSS 9.8No exploitEPSS 2%

    nxp · mqxMay 3, 2022

  • NXP MCUXpresso SDK Integer Overflow or Wraparound

    CriticalCVSS 9.8No exploitEPSS 1%

    nxp · mcuxpresso software development kitMay 3, 2022

  • The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length,

    HighCVSS 8.8No exploitEPSS 1%

    nxp · mcuxpresso software development kitFeb 12, 2020

  • NXP LPC55S66JBD64, LPC55S66JBD100, LPC55S66JEV98, LPC55S69JBD64, LPC55S69JBD100, and LPC55S69JEV98 microcontrollers (ROM version 1B) have a

    HighCVSS 7.8No exploitEPSS 1%

    nxp · lpc55s66jbd64 firmwareMar 23, 2022

  • An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0.

    HighCVSS 7.8No exploitEPSS 0%

    trustedfirmware · op-teeDec 7, 2021

  • NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor().

    HighCVSS 7.8No exploitEPSS 0%

    nxp · mcuxpresso software development kitOct 25, 2021

  • NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().

    HighCVSS 7.8No exploitEPSS 0%

    nxp · mcuxpresso software development kitOct 25, 2021

  • A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family proces

    HighCVSS 7.8No exploitEPSS 0%

    nxp · uboot secondary program loaderOct 17, 2023

  • The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass becau

    HighCVSS 7.1No exploitEPSS 0%

    nxp · i.mx 6Dec 7, 2021

  • NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x, LPC55S2x, LPC552x

    MediumCVSS 6.8No exploitEPSS 0%

    nxp · lpc55s69jbd100 firmwareMay 6, 2021

  • The Bluetooth Low Energy (BLE) stack implementation on the NXP KW41Z (based on the MCUXpresso SDK with Bluetooth Low Energy Driver 2.2.1 and

    MediumCVSS 6.5No exploitEPSS 1%

    nxp · mcuxpresso software development kitFeb 10, 2020

  • On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only ac

    MediumCVSS 6.6No exploitEPSS 0%

    nxp · kinetis kv1x firmwareSep 24, 2019

  • CVE-2017-7936
    25Monitor

    A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6Du

    MediumCVSS 6.3No exploitEPSS 0%

    nxp · vybrid mvf30nn151cku26 firmwareAug 7, 2017

  • CVE-2017-7932
    24Monitor

    An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, V

    MediumCVSS 6.0No exploitEPSS 0%

    nxp · vybrid mvf30nn151cku26 firmwareAug 7, 2017

  • NXP LPC55S69 devices before A3 have a buffer over-read via a crafted wlength value in a GET Descriptor Configuration request during use of U

    MediumCVSS 5.5Proof of conceptEPSS 1%

    nxp · lpc55s69jbd100 firmwareDec 1, 2021

  • NXP Kinetis K82 devices have a buffer over-read via a crafted wlength value in a GET Status-Other request during use of USB In-System Progra

    MediumCVSS 5.5No exploitEPSS 0%

    nxp · kinetis k82 firmwareDec 1, 2021

  • An information-disclosure vulnerability exists on select NXP devices when configured in Serial Download Protocol (SDP) mode: i.MX RT 1010, i

    MediumCVSS 4.6No exploitEPSS 1%

    nxp · i.mx 6 firmwareNov 18, 2022

  • On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) over RFID to bypass a

    MediumCVSS 4.2No exploitEPSS 0%

    nxp · mifare ultralight ev1 firmwareJun 6, 2021

  • CVE-2021-3011
    16Monitor

    An electromagnetic-wave side-channel issue was discovered on NXP SmartMX / P5x security microcontrollers and A7x secure authentication micro

    MediumCVSS 4.2No exploitEPSS 0%

    nxp · 3a081Jan 7, 2021