Skip to content
Noroxi

TrustedFirmware records

85 published records for vendor trustedfirmware.

Researcher profile

Entered KEV
1 · 1.2%
Weaponized
1 · 1.2%
Pre-auth RCE
6
With a fix record
49.4%
Median publish → KEV
162 days

All records

85 records
  • In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure da

    MediumCVSS 5.5KEVWeaponizedEPSS 3%

    trustedfirmware · trusted firmware-mMay 25, 2021

  • Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    trustedfirmware · op-teeJul 15, 2019

  • Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.

    CriticalCVSS 9.8No exploitEPSS 3%

    trustedfirmware · op-teeJul 15, 2019

  • Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.

    CriticalCVSS 9.8No exploitEPSS 3%

    trustedfirmware · op-teeJul 15, 2019

  • Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.

    CriticalCVSS 9.8No exploitEPSS 3%

    arm · mbed tlsDec 20, 2021

  • Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.

    CriticalCVSS 9.8No exploitEPSS 2%

    trustedfirmware · op-teeJul 15, 2019

  • Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing.

    CriticalCVSS 9.8No exploitEPSS 2%

    trustedfirmware · op-teeJul 15, 2019

  • Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks.

    CriticalCVSS 9.8No exploitEPSS 2%

    trustedfirmware · op-teeJul 16, 2019

  • Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.

    CriticalCVSS 9.8No exploitEPSS 1%

    trustedfirmware · mbed tlsOct 6, 2023

  • An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    arm · mbed tlsDec 15, 2022

  • An issue was discovered in Trusted Firmware-M through 2.1.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    Oct 9, 2024

  • An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    arm · mbed tlsApr 2, 2026

  • An issue was discovered in Mbed TLS 3.6 before 3.6.1.

    CriticalCVSS 9.8No exploitEPSS 1%

    trustedfirmware · mbed tlsSep 5, 2024

  • Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair

    CriticalCVSS 9.8No exploitEPSS 1%

    trustedfirmware · mbed tlsOct 15, 2024

  • An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0.

    CriticalCVSS 9.8No exploitEPSS 1%

    trustedfirmware · mbed tlsApr 1, 2026

  • An issue was discovered in Mbed TLS 3.x before 3.6.1.

    CriticalCVSS 9.8No exploitEPSS 0%

    trustedfirmware · mbed tlsSep 5, 2024

  • An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0.

    CriticalCVSS 9.1No exploitEPSS 2%

    arm · mbed tlsJul 15, 2022

  • In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions dire

    CriticalCVSS 9.1No exploitEPSS 1%

    trustedfirmware · op-teeAug 11, 2021

  • In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack

    CriticalCVSS 9.1No exploitEPSS 1%

    trustedfirmware · mbed tlsApr 2, 2024

  • An issue was discovered in Mbed TLS 3.5.0 through 4.0.0.

    CriticalCVSS 9.1No exploitEPSS 0%

    trustedfirmware · mbed tlsApr 1, 2026

  • OP-TEE Trusted OS vulnerable to Improper Validation of Array Index in the cleanup_shm_refs function

    HighCVSS 8.8Proof of conceptEPSS 0%

    trustedfirmware · op-teeNov 29, 2022

  • OP-TEE: PKCS#11 TA out-of-bounds read and memory disclosure

    HighCVSS 8.7Proof of conceptEPSS 0%

    trustedfirmware · op-teeApr 23, 2026

  • CVE-2017-2784
    33Monitor

    An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2

    HighCVSS 8.1No exploitEPSS 3%

    trustedfirmware · mbed tlsApr 20, 2017

  • ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentica

    HighCVSS 8.1No exploitEPSS 2%

    arm · mbed tlsAug 30, 2017

  • CVE-2017-7563
    32Monitor

    In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protect

    HighCVSS 8.1No exploitEPSS 1%

    trustedfirmware · trusted firmware-aJun 7, 2017