TrustedFirmware records
85 published records for vendor trustedfirmware.
Researcher profile
- Entered KEV
- 1 · 1.2%
- Weaponized
- 1 · 1.2%
- Pre-auth RCE
- 6
- With a fix record
- 49.4%
- Median publish → KEV
- 162 days
Recurring classes
- CWE-125 Out-of-bounds Read8
- CWE-190 Integer Overflow or Wraparound7
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-787 Out-of-bounds Write5
- CWE-20 Improper Input Validation4
- CWE-121 Stack-based Buffer Overflow4
The weakness classes this vendor ships most often: where to look.
CWEAll records
85 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2021-27562Weaponized | In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure datrustedfirmware · trusted firmware-m · CWE-787 | Medium5.5 | KEV | 3.1% | May 25, 2021 |
40Plan | CVE-2019-1010298Proof of concept | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.trustedfirmware · op-tee · CWE-190 | Critical9.8 | — | 3.9% | Jul 15, 2019 |
40Plan | CVE-2019-1010296No exploit | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.trustedfirmware · op-tee · CWE-190 | Critical9.8 | — | 2.8% | Jul 15, 2019 |
40Plan | CVE-2019-1010297No exploit | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.trustedfirmware · op-tee · CWE-190 | Critical9.8 | — | 2.7% | Jul 15, 2019 |
40Plan | CVE-2021-44732No exploit | Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.arm · mbed tls · CWE-415 | Critical9.8 | — | 2.6% | Dec 20, 2021 |
39Monitor | CVE-2019-1010295No exploit | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.trustedfirmware · op-tee · CWE-20 | Critical9.8 | — | 1.6% | Jul 15, 2019 |
39Monitor | CVE-2019-1010293No exploit | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing.trustedfirmware · op-tee · CWE-787 | Critical9.8 | — | 1.6% | Jul 15, 2019 |
39Monitor | CVE-2019-1010292No exploit | Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks.trustedfirmware · op-tee · CWE-787 | Critical9.8 | — | 1.6% | Jul 16, 2019 |
39Monitor | CVE-2023-45199No exploit | Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.trustedfirmware · mbed tls · CWE-120 | Critical9.8 | — | 1.3% | Oct 6, 2023 |
39Monitor | CVE-2022-46393No exploit | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0.arm · mbed tls · CWE-125 | Critical9.8 | — | 1.2% | Dec 15, 2022 |
39Monitor | CVE-2024-45746No exploit | An issue was discovered in Trusted Firmware-M through 2.1.0.CWE-120 | Critical9.8 | — | 0.8% | Oct 9, 2024 |
39Monitor | CVE-2026-34877No exploit | An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0.arm · mbed tls · CWE-250 | Critical9.8 | — | 0.7% | Apr 2, 2026 |
39Monitor | CVE-2024-45158No exploit | An issue was discovered in Mbed TLS 3.6 before 3.6.1.trustedfirmware · mbed tls · CWE-121 | Critical9.8 | — | 0.7% | Sep 5, 2024 |
39Monitor | CVE-2024-49195No exploit | Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pairtrustedfirmware · mbed tls · CWE-787 | Critical9.8 | — | 0.6% | Oct 15, 2024 |
39Monitor | CVE-2026-34875No exploit | An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0.trustedfirmware · mbed tls · CWE-120 | Critical9.8 | — | 0.6% | Apr 1, 2026 |
39Monitor | CVE-2024-45159No exploit | An issue was discovered in Mbed TLS 3.x before 3.6.1.trustedfirmware · mbed tls · CWE-295 | Critical9.8 | — | 0.4% | Sep 5, 2024 |
37Monitor | CVE-2022-35409No exploit | An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0.arm · mbed tls · CWE-125 | Critical9.1 | — | 2.3% | Jul 15, 2022 |
36Monitor | CVE-2019-25052No exploit | In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions diretrustedfirmware · op-tee · CWE-327 | Critical9.1 | — | 0.9% | Aug 11, 2021 |
36Monitor | CVE-2024-30166No exploit | In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack trustedfirmware · mbed tls · CWE-121 | Critical9.1 | — | 0.7% | Apr 2, 2024 |
36Monitor | CVE-2026-34873No exploit | An issue was discovered in Mbed TLS 3.5.0 through 4.0.0.trustedfirmware · mbed tls · CWE-287 | Critical9.1 | — | 0.4% | Apr 1, 2026 |
35Monitor | CVE-2022-46152Proof of concept | OP-TEE Trusted OS vulnerable to Improper Validation of Array Index in the cleanup_shm_refs functiontrustedfirmware · op-tee · CWE-129 | High8.8 | — | 0.5% | Nov 29, 2022 |
34Monitor | CVE-2026-33317Proof of concept | OP-TEE: PKCS#11 TA out-of-bounds read and memory disclosuretrustedfirmware · op-tee · CWE-125 | High8.7 | — | 0.2% | Apr 23, 2026 |
33Monitor | CVE-2017-2784No exploit | An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2trustedfirmware · mbed tls · CWE-295 | High8.1 | — | 3.4% | Apr 20, 2017 |
32Monitor | CVE-2017-14032No exploit | ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authenticaarm · mbed tls · CWE-287 | High8.1 | — | 1.5% | Aug 30, 2017 |
32Monitor | CVE-2017-7563No exploit | In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protecttrustedfirmware · trusted firmware-a · CWE-732 | High8.1 | — | 0.9% | Jun 7, 2017 |
- CVE-2021-2756253Plan
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure da
MediumCVSS 5.5KEVWeaponizedEPSS 3%trustedfirmware · trusted firmware-mMay 25, 2021
- CVE-2019-101029840Plan
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.
CriticalCVSS 9.8Proof of conceptEPSS 4%trustedfirmware · op-teeJul 15, 2019
- CVE-2019-101029640Plan
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.
CriticalCVSS 9.8No exploitEPSS 3%trustedfirmware · op-teeJul 15, 2019
- CVE-2019-101029740Plan
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.
CriticalCVSS 9.8No exploitEPSS 3%trustedfirmware · op-teeJul 15, 2019
- CVE-2021-4473240Plan
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
CriticalCVSS 9.8No exploitEPSS 3%arm · mbed tlsDec 20, 2021
- CVE-2019-101029539Monitor
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.
CriticalCVSS 9.8No exploitEPSS 2%trustedfirmware · op-teeJul 15, 2019
- CVE-2019-101029339Monitor
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing.
CriticalCVSS 9.8No exploitEPSS 2%trustedfirmware · op-teeJul 15, 2019
- CVE-2019-101029239Monitor
Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks.
CriticalCVSS 9.8No exploitEPSS 2%trustedfirmware · op-teeJul 16, 2019
- CVE-2023-4519939Monitor
Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
CriticalCVSS 9.8No exploitEPSS 1%trustedfirmware · mbed tlsOct 6, 2023
- CVE-2022-4639339Monitor
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0.
CriticalCVSS 9.8No exploitEPSS 1%arm · mbed tlsDec 15, 2022
- CVE-2024-4574639Monitor
An issue was discovered in Trusted Firmware-M through 2.1.0.
CriticalCVSS 9.8No exploitEPSS 1%Oct 9, 2024
- CVE-2026-3487739Monitor
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0.
CriticalCVSS 9.8No exploitEPSS 1%arm · mbed tlsApr 2, 2026
- CVE-2024-4515839Monitor
An issue was discovered in Mbed TLS 3.6 before 3.6.1.
CriticalCVSS 9.8No exploitEPSS 1%trustedfirmware · mbed tlsSep 5, 2024
- CVE-2024-4919539Monitor
Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
CriticalCVSS 9.8No exploitEPSS 1%trustedfirmware · mbed tlsOct 15, 2024
- CVE-2026-3487539Monitor
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0.
CriticalCVSS 9.8No exploitEPSS 1%trustedfirmware · mbed tlsApr 1, 2026
- CVE-2024-4515939Monitor
An issue was discovered in Mbed TLS 3.x before 3.6.1.
CriticalCVSS 9.8No exploitEPSS 0%trustedfirmware · mbed tlsSep 5, 2024
- CVE-2022-3540937Monitor
An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0.
CriticalCVSS 9.1No exploitEPSS 2%arm · mbed tlsJul 15, 2022
- CVE-2019-2505236Monitor
In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions dire
CriticalCVSS 9.1No exploitEPSS 1%trustedfirmware · op-teeAug 11, 2021
- CVE-2024-3016636Monitor
In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack
CriticalCVSS 9.1No exploitEPSS 1%trustedfirmware · mbed tlsApr 2, 2024
- CVE-2026-3487336Monitor
An issue was discovered in Mbed TLS 3.5.0 through 4.0.0.
CriticalCVSS 9.1No exploitEPSS 0%trustedfirmware · mbed tlsApr 1, 2026
- CVE-2022-4615235Monitor
OP-TEE Trusted OS vulnerable to Improper Validation of Array Index in the cleanup_shm_refs function
HighCVSS 8.8Proof of conceptEPSS 0%trustedfirmware · op-teeNov 29, 2022
- CVE-2026-3331734Monitor
OP-TEE: PKCS#11 TA out-of-bounds read and memory disclosure
HighCVSS 8.7Proof of conceptEPSS 0%trustedfirmware · op-teeApr 23, 2026
- CVE-2017-278433Monitor
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2
HighCVSS 8.1No exploitEPSS 3%trustedfirmware · mbed tlsApr 20, 2017
- CVE-2017-1403232Monitor
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentica
HighCVSS 8.1No exploitEPSS 2%arm · mbed tlsAug 30, 2017
- CVE-2017-756332Monitor
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protect
HighCVSS 8.1No exploitEPSS 1%trustedfirmware · trusted firmware-aJun 7, 2017