Записи TrustedFirmware
85 опубликованных записей вендора trustedfirmware.
Профиль для исследователя
- Попали в KEV
- 1 · 1,2 %
- С эксплойтом
- 1 · 1,2 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 49,4 %
- Медиана: публикация → KEV
- 162 дн.
Повторяющиеся классы
- CWE-125 Out-of-bounds Read8
- CWE-190 Integer Overflow or Wraparound7
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')5
- CWE-787 Out-of-bounds Write5
- CWE-20 Improper Input Validation4
- CWE-121 Stack-based Buffer Overflow4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
85 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2021-27562Готовый эксплойт | In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure datrustedfirmware · trusted firmware-m · CWE-787 | Средняя5,5 | KEV | 3,1 % | 25 мая 2021 г. |
40В плане | CVE-2019-1010298Proof of concept | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.trustedfirmware · op-tee · CWE-190 | Критическая9,8 | — | 3,9 % | 15 июл. 2019 г. |
40В плане | CVE-2019-1010296Эксплойта нет | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.trustedfirmware · op-tee · CWE-190 | Критическая9,8 | — | 2,8 % | 15 июл. 2019 г. |
40В плане | CVE-2019-1010297Эксплойта нет | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.trustedfirmware · op-tee · CWE-190 | Критическая9,8 | — | 2,7 % | 15 июл. 2019 г. |
40В плане | CVE-2021-44732Эксплойта нет | Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.arm · mbed tls · CWE-415 | Критическая9,8 | — | 2,6 % | 20 дек. 2021 г. |
39Наблюдать | CVE-2019-1010295Эксплойта нет | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.trustedfirmware · op-tee · CWE-20 | Критическая9,8 | — | 1,6 % | 15 июл. 2019 г. |
39Наблюдать | CVE-2019-1010293Эксплойта нет | Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing.trustedfirmware · op-tee · CWE-787 | Критическая9,8 | — | 1,6 % | 15 июл. 2019 г. |
39Наблюдать | CVE-2019-1010292Эксплойта нет | Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks.trustedfirmware · op-tee · CWE-787 | Критическая9,8 | — | 1,6 % | 16 июл. 2019 г. |
39Наблюдать | CVE-2022-46393Эксплойта нет | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0.arm · mbed tls · CWE-125 | Критическая9,8 | — | 1,2 % | 15 дек. 2022 г. |
39Наблюдать | CVE-2023-45199Эксплойта нет | Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.trustedfirmware · mbed tls · CWE-120 | Критическая9,8 | — | 1,1 % | 6 окт. 2023 г. |
39Наблюдать | CVE-2024-45746Эксплойта нет | An issue was discovered in Trusted Firmware-M through 2.1.0.CWE-120 | Критическая9,8 | — | 0,8 % | 9 окт. 2024 г. |
39Наблюдать | CVE-2026-34877Эксплойта нет | An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0.arm · mbed tls · CWE-250 | Критическая9,8 | — | 0,7 % | 2 апр. 2026 г. |
39Наблюдать | CVE-2024-45158Эксплойта нет | An issue was discovered in Mbed TLS 3.6 before 3.6.1.trustedfirmware · mbed tls · CWE-121 | Критическая9,8 | — | 0,7 % | 5 сент. 2024 г. |
39Наблюдать | CVE-2024-49195Эксплойта нет | Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pairtrustedfirmware · mbed tls · CWE-787 | Критическая9,8 | — | 0,6 % | 15 окт. 2024 г. |
39Наблюдать | CVE-2026-34875Эксплойта нет | An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0.trustedfirmware · mbed tls · CWE-120 | Критическая9,8 | — | 0,6 % | 1 апр. 2026 г. |
39Наблюдать | CVE-2024-45159Эксплойта нет | An issue was discovered in Mbed TLS 3.x before 3.6.1.trustedfirmware · mbed tls · CWE-295 | Критическая9,8 | — | 0,4 % | 5 сент. 2024 г. |
37Наблюдать | CVE-2022-35409Эксплойта нет | An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0.arm · mbed tls · CWE-125 | Критическая9,1 | — | 2,2 % | 15 июл. 2022 г. |
36Наблюдать | CVE-2019-25052Эксплойта нет | In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions diretrustedfirmware · op-tee · CWE-327 | Критическая9,1 | — | 0,9 % | 11 авг. 2021 г. |
36Наблюдать | CVE-2024-30166Эксплойта нет | In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack trustedfirmware · mbed tls · CWE-121 | Критическая9,1 | — | 0,7 % | 2 апр. 2024 г. |
36Наблюдать | CVE-2026-34873Эксплойта нет | An issue was discovered in Mbed TLS 3.5.0 through 4.0.0.trustedfirmware · mbed tls · CWE-287 | Критическая9,1 | — | 0,4 % | 1 апр. 2026 г. |
35Наблюдать | CVE-2022-46152Proof of concept | OP-TEE Trusted OS vulnerable to Improper Validation of Array Index in the cleanup_shm_refs functiontrustedfirmware · op-tee · CWE-129 | Высокая8,8 | — | 0,5 % | 29 нояб. 2022 г. |
34Наблюдать | CVE-2026-33317Proof of concept | OP-TEE: PKCS#11 TA out-of-bounds read and memory disclosuretrustedfirmware · op-tee · CWE-125 | Высокая8,7 | — | 0,2 % | 23 апр. 2026 г. |
33Наблюдать | CVE-2017-2784Эксплойта нет | An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2trustedfirmware · mbed tls · CWE-295 | Высокая8,1 | — | 3,4 % | 20 апр. 2017 г. |
32Наблюдать | CVE-2017-14032Эксплойта нет | ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authenticaarm · mbed tls · CWE-287 | Высокая8,1 | — | 1,5 % | 30 авг. 2017 г. |
32Наблюдать | CVE-2017-7563Эксплойта нет | In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protecttrustedfirmware · trusted firmware-a · CWE-732 | Высокая8,1 | — | 0,9 % | 7 июн. 2017 г. |
- CVE-2021-2756253В плане
In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure da
СредняяCVSS 5,5KEVГотовый эксплойтEPSS 3 %trustedfirmware · trusted firmware-m25 мая 2021 г.
- CVE-2019-101029840В плане
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %trustedfirmware · op-tee15 июл. 2019 г.
- CVE-2019-101029640В плане
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %trustedfirmware · op-tee15 июл. 2019 г.
- CVE-2019-101029740В плане
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %trustedfirmware · op-tee15 июл. 2019 г.
- CVE-2021-4473240В плане
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %arm · mbed tls20 дек. 2021 г.
- CVE-2019-101029539Наблюдать
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %trustedfirmware · op-tee15 июл. 2019 г.
- CVE-2019-101029339Наблюдать
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %trustedfirmware · op-tee15 июл. 2019 г.
- CVE-2019-101029239Наблюдать
Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %trustedfirmware · op-tee16 июл. 2019 г.
- CVE-2022-4639339Наблюдать
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %arm · mbed tls15 дек. 2022 г.
- CVE-2023-4519939Наблюдать
Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %trustedfirmware · mbed tls6 окт. 2023 г.
- CVE-2024-4574639Наблюдать
An issue was discovered in Trusted Firmware-M through 2.1.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %9 окт. 2024 г.
- CVE-2026-3487739Наблюдать
An issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %arm · mbed tls2 апр. 2026 г.
- CVE-2024-4515839Наблюдать
An issue was discovered in Mbed TLS 3.6 before 3.6.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %trustedfirmware · mbed tls5 сент. 2024 г.
- CVE-2024-4919539Наблюдать
Mbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque key pair
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %trustedfirmware · mbed tls15 окт. 2024 г.
- CVE-2026-3487539Наблюдать
An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %trustedfirmware · mbed tls1 апр. 2026 г.
- CVE-2024-4515939Наблюдать
An issue was discovered in Mbed TLS 3.x before 3.6.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %trustedfirmware · mbed tls5 сент. 2024 г.
- CVE-2022-3540937Наблюдать
An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %arm · mbed tls15 июл. 2022 г.
- CVE-2019-2505236Наблюдать
In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions dire
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %trustedfirmware · op-tee11 авг. 2021 г.
- CVE-2024-3016636Наблюдать
In Mbed TLS 3.3.0 through 3.5.2 before 3.6.0, a malicious client can cause information disclosure or a denial of service because of a stack
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %trustedfirmware · mbed tls2 апр. 2024 г.
- CVE-2026-3487336Наблюдать
An issue was discovered in Mbed TLS 3.5.0 through 4.0.0.
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %trustedfirmware · mbed tls1 апр. 2026 г.
- CVE-2022-4615235Наблюдать
OP-TEE Trusted OS vulnerable to Improper Validation of Array Index in the cleanup_shm_refs function
ВысокаяCVSS 8,8Proof of conceptEPSS 0 %trustedfirmware · op-tee29 нояб. 2022 г.
- CVE-2026-3331734Наблюдать
OP-TEE: PKCS#11 TA out-of-bounds read and memory disclosure
ВысокаяCVSS 8,7Proof of conceptEPSS 0 %trustedfirmware · op-tee23 апр. 2026 г.
- CVE-2017-278433Наблюдать
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %trustedfirmware · mbed tls20 апр. 2017 г.
- CVE-2017-1403232Наблюдать
ARM mbed TLS before 1.3.21 and 2.x before 2.1.9, if optional authentication is configured, allows remote attackers to bypass peer authentica
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %arm · mbed tls30 авг. 2017 г.
- CVE-2017-756332Наблюдать
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protect
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %trustedfirmware · trusted firmware-a7 июн. 2017 г.