Samsung / Mtower
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-40757 | A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACComputeFinal function in Samsung mTower through 0.3.0 allows a trusted application to tr… | HIGH | 7.5 | Sep 16, 2022 |
| CVE-2022-40758 | A Buffer Access with Incorrect Length Value vulnerablity in the TEE_CipherUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigg… | HIGH | 7.5 | Sep 16, 2022 |
| CVE-2022-40759 | A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Servic… | HIGH | 7.5 | Sep 16, 2022 |
| CVE-2022-40760 | A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger… | HIGH | 7.5 | Sep 16, 2022 |
| CVE-2022-40761 | The function tee_obj_free in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_Alloca… | HIGH | 7.5 | Sep 16, 2022 |
| CVE-2022-40762 | A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 allows a trusted application to trigger… | HIGH | 7.5 | Sep 16, 2022 |
| CVE-2022-39828 | sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading to a denial of service. | HIGH | 7.5 | Sep 5, 2022 |
| CVE-2022-39829 | There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new. | HIGH | 7.5 | Sep 5, 2022 |
| CVE-2022-39830 | sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coordinates, leading to a denial of servic… | HIGH | 7.5 | Sep 5, 2022 |
| CVE-2022-36622 | Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1. | HIGH | 7.5 | Sep 1, 2022 |
| CVE-2022-36621 | Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject. | HIGH | 7.5 | Sep 1, 2022 |
| CVE-2022-38155 | TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numa… | HIGH | 7.5 | Aug 11, 2022 |
| CVE-2022-35858 | The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of ser… | HIGH | 7.8 | Aug 4, 2022 |
Showing 1 to 13 of 13 CVEs