Show filters
440 Total Results
Displaying 251-260 of 440
Sort by:
Attacker Value
Unknown
CVE-2021-27431
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalent) function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or injected code execution.
0
Attacker Value
Unknown
CVE-2021-43666
Disclosure Date: March 24, 2022 (last updated October 07, 2023)
A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.
0
Attacker Value
Unknown
CVE-2022-23960
Disclosure Date: March 13, 2022 (last updated October 07, 2023)
Certain Arm Cortex and Neoverse processors through 2022-03-08 do not properly restrict cache speculation, aka Spectre-BHB. An attacker can leverage the shared branch history in the Branch History Buffer (BHB) to influence mispredicted branches. Then, cache allocation can allow the attacker to obtain sensitive information.
0
Attacker Value
Unknown
CVE-2022-25368
Disclosure Date: March 10, 2022 (last updated October 07, 2023)
Spectre BHB is a variant of Spectre-v2 in which malicious code uses the shared branch history (stored in the CPU BHB) to influence mispredicted branches in the victim's hardware context. Speculation caused by these mispredicted branches can then potentially be used to cause cache allocation, which can then be used to infer information that should be protected.
0
Attacker Value
Unknown
CVE-2022-22706
Disclosure Date: March 03, 2022 (last updated February 23, 2025)
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.
0
Attacker Value
Unknown
CVE-2021-43619
Disclosure Date: March 01, 2022 (last updated February 23, 2025)
Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a psa_fwu_write caller from SPE or NSPE can overwrite stack memory locations.
0
Attacker Value
Unknown
CVE-2021-44331
Disclosure Date: February 28, 2022 (last updated February 23, 2025)
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow in function encode_ise().
0
Attacker Value
Unknown
CVE-2021-43086
Disclosure Date: February 28, 2022 (last updated February 23, 2025)
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in "/Source/astcenc_compress_symbolic.cpp".
0
Attacker Value
Unknown
CVE-2021-23495
Disclosure Date: February 25, 2022 (last updated February 23, 2025)
The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter.
0
Attacker Value
Unknown
CVE-2022-23627
Disclosure Date: February 08, 2022 (last updated February 23, 2025)
ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`) commands. In particular, a proxy-like command sent to bot `A` targeting bot `B` has incorrectly verified user's access against bot `A` - instead of bot `B`, to which the command was originally designated. This in result allowed access to resources beyond those configured, being a security threat affecting confidentiality of other bot instances. A successful attack exploiting this bug requires a significant access granted explicitly by original owner of the ASF process prior to that, as attacker has to control at least a single bot in the process to make use of this inadequate access verification loophole. The issue is patched in ASF V5.2.2.5, V5.2.3.2 and future versions. Users are advised to update as soon as po…
0