Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2022-40762

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_Realloc with an excessive number for the parameter len.
Attacker Value
Unknown

CVE-2022-40761

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
The function tee_obj_free in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_AllocateOperation with a disturbed heap layout, related to utee_cryp_obj_alloc.
Attacker Value
Unknown

CVE-2022-40760

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACUpdate with an excessive size value of chunkSize.
Attacker Value
Unknown

CVE-2022-40759

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACCompareFinal with a NULL pointer for the parameter operation.
Attacker Value
Unknown

CVE-2022-40758

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
A Buffer Access with Incorrect Length Value vulnerablity in the TEE_CipherUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_CipherUpdate with an excessive size value of srcLen.
Attacker Value
Unknown

CVE-2022-40757

Disclosure Date: September 16, 2022 (last updated February 24, 2025)
A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACComputeFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACComputeFinal with an excessive size value of messageLen.
Attacker Value
Unknown

CVE-2022-39830

Disclosure Date: September 05, 2022 (last updated October 08, 2023)
sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coordinates, leading to a denial of service.
Attacker Value
Unknown

CVE-2022-39829

Disclosure Date: September 05, 2022 (last updated February 24, 2025)
There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new.
Attacker Value
Unknown

CVE-2022-39828

Disclosure Date: September 05, 2022 (last updated October 08, 2023)
sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading to a denial of service.
Attacker Value
Unknown

CVE-2022-36622

Disclosure Date: September 01, 2022 (last updated February 24, 2025)
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1.