Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2022-36621

Disclosure Date: September 01, 2022 (last updated February 24, 2025)
Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject.
Attacker Value
Unknown

CVE-2022-38155

Disclosure Date: August 11, 2022 (last updated February 24, 2025)
TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numaker-PFM-M2351 TEE kernel crash.
Attacker Value
Unknown

CVE-2022-35858

Disclosure Date: August 04, 2022 (last updated February 24, 2025)
The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of service, and information disclosure by invoking the function TEE_PopulateTransientObject with a large number in the parameter attrCount.