Vulnerabilities (CVE)

Filtered by vendor Arm Subscribe
Filtered by product Arm-trusted-firmware
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-15031 1 Arm 1 Arm-trusted-firmware 2024-02-04 5.0 MEDIUM 7.5 HIGH
In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.
CVE-2017-9607 1 Arm 1 Arm-trusted-firmware 2024-02-04 5.1 MEDIUM 7.0 HIGH
The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure memory, bypass the bl1_plat_mem_check protection mechanism, cause a denial of service, or possibly have unspecified other impact via a crafted AArch32 image, which triggers an integer overflow.