RSS   Vulnerabilities for 'Cortex-a'   RSS

2018-07-10
 
CVE-2018-3693

CWE-noinfo
 

 
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.

 
2018-06-21
 
CVE-2018-3665

CWE-200
 

 
System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.

 
2018-05-22
 
CVE-2018-3640

CWE-200
 

 
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.

 
 
CVE-2018-3639

CWE-200
 

 
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

 
2018-03-27
 
CVE-2018-9056

CWE-200
 

 
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope.

 
2018-01-04
 
CVE-2017-5754

CWE-200
 

 
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

 
 
CVE-2017-5753

CWE-200
 

 
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

 
 
CVE-2017-5715

CWE-200
 

 
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

 

 >>> Vendor: ARM 16 Products
Mbed tls
Arm trusted firmware
Arm-trusted-firmware
Cortex-a
Cortex-r
Trusted firmware-a
Mbed crypto
Mbed os
Arm compiler
Trusted firmware-m
Cortex-a72
Bifrost gpu kernel driver
Midguard gpu kernel driver
Valhall gpu kernel driver
Adaptive scalable texture compression encoder
Astc encoder


Copyright 2024, cxsecurity.com

 

Back to Top