Where
-Infinity
0

OP-TEE OP-TEEOP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication guarantee

Risk 20
Severity
3.8
First published (updated )

OP-TEE Op-tee OsOP-TEE's subkey rollback protection can be bypassed with older subkey versions

Risk 32
Severity
5.5
First published (updated )

OP-TEE OP-TEEOP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references

Risk 20
Severity
3.8
First published (updated )

OP-TEE OP-TEEOP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle

Risk 18
Severity
3.3
First published (updated )

OP-TEE OP-TEEOP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery

Risk 18
Severity
3.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OP-TEE OP-TEEOP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery

Risk 18
Severity
3.3
First published (updated )

OP-TEE OP-TEEOP-TEE has unbounded recursion in sanitize_client_object()

Risk 18
Severity
3.3
First published (updated )

OP-TEE Op-tee OsOP-TEE has SHA-3 accelerated finalize heap overflow

Risk 32
Severity
5.5
First published (updated )

OP-TEE Op-tee OsOP-TEE has FF-A type confusion in SPMC tmem path that causes S-EL1 kernel panic

Risk 32
Severity
5.5
First published (updated )

OP-TEE OP-TEEOP-TEE vulnerable to ECDH private key recovery

Risk 28
Severity
4.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

OP-TEE OP-TEEOP-TEE has a Use-After-Free race in FF-A shared-memory teardown

Risk 69
Severity
7.8
First published (updated )

OP-TEE OP-TEEOP-TEE: RSASSA EMSA- PKCS1-v1_5 underflow in emsa_pkcs1_v1_5_encode()

Risk 43
Severity
7.5
First published (updated )

OP-TEE OP-TEEOP-TEE: PKCS#11 TA out-of-bounds read and memory disclosure

Risk 68
Severity
8.7
First published (updated )

TrustedFirmware Mbed TlsAn issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds read vulnerability in mbedtls…

Risk 43
Severity
7.5
First published (updated )

Arm mbed TLSAn issue was discovered in Mbed TLS versions from 2.19.0 up to 3.6.5, Mbed TLS 4.0.0. Insufficient p…

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

TrustedFirmware Mbed TlsMbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.

Risk 40
Severity
6.5
First published (updated )

Arm mbed TLSMbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a Pseudo-Random Number Generato…

Risk 56
Severity
7.7
First published (updated )

TrustedFirmware Mbed TlsBuffer Overflow

Risk 43
Severity
7.5
First published (updated )

TrustedFirmware Mbed TlsBuffer Overflow

Risk 86
Severity
9.8
First published (updated )

TrustedFirmware Mbed TlsNull Pointer Dereference

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Arm mbed TLSWeak RNG

Risk 50
Severity
6.7
First published (updated )

TrustedFirmware Mbed TlsAn issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impersonation can occur while resumi…

Risk 66
Severity
9.1
First published (updated )

TrustedFirmware Trusted Firmware-mTrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2.1.3 and 2.2.x before 2.2.1 …

Risk 64
Severity
8.6
First published (updated )

Mbed TLS Mbed TLSIn Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal a…

Risk 22
Severity
4
First published (updated )

Arm MbedTLSIn MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_verify may accept invalid signatures if hash computation …

Risk 28
Severity
4.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MbedTLS MbedTLSIn MbedTLS 3.3.0 before 3.6.4, mbedtls_lms_import_public_key does not check that the input buffer is…

Risk 40
Severity
6.5
First published (updated )

Arm mbed TLSMbed TLS before 2.28.10 and 3.x before 3.6.3, on the client side, accepts servers that have trusted …

Risk 26
Severity
5.4
EPSS
0.03%
First published (updated )

Mbed TLS Mbed TLSMbed TLS before 2.28.10 and 3.x before 3.6.3, in some cases of failed memory allocation or hardware …

Risk 26
Severity
5.4
EPSS
0.05%
First published (updated )

Arm mbed TLSMbed TLS 3.5.x through 3.6.x before 3.6.2 has a buffer underrun in pkwrite when writing an opaque ke…

Risk 61
Severity
9.8
EPSS
0.14%
First published (updated )

TrustedFirmware Trusted Firmware-mAn issue was discovered in Trusted Firmware-M through 2.0.0. The lack of argument verification in th…

Risk 25
Severity
4.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203