Vulnerabilities (CVE)

Filtered by vendor Nxp Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44149 2 Linaro, Nxp 2 Op-tee, I.mx 6ultralite 2022-07-12 4.6 MEDIUM 7.8 HIGH
An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL SoC devices lacks security access configuration for wakeup-related registers, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a v cycle.
CVE-2021-36133 2 Linaro, Nxp 7 Op-tee, I.mx6sx, I.mx 6 and 4 more 2021-12-09 3.6 LOW 7.1 HIGH
The OPTEE-OS CSU driver for NXP i.MX SoC devices lacks security access configuration for several models, resulting in TrustZone bypass because the NonSecure World can perform arbitrary memory read/write operations on Secure World memory. This involves a DMA capable peripheral.
CVE-2021-38260 1 Nxp 1 Mcuxpresso Software Development Kit 2021-10-28 4.6 MEDIUM 7.8 HIGH
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor().
CVE-2021-38258 1 Nxp 1 Mcuxpresso Software Development Kit 2021-10-28 4.6 MEDIUM 7.8 HIGH
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().
CVE-2019-17519 1 Nxp 2 Kw41z, Kw41z Sdk 2020-02-25 5.8 MEDIUM 8.8 HIGH
The Bluetooth Low Energy implementation on NXP SDK through 2.2.1 for KW41Z devices does not properly restrict the Link Layer payload length, allowing attackers in radio range to cause a buffer overflow via a crafted packet.