Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 215 respecto a la semana anterior
Críticas / altas1379▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.11% | — | Samsung MtowerAI | 1/9/2026 | 1/9/2026 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be. | |
| Aplazada | Media (5.5) | 0.15% | — | Samsung MtowerAI | 1/9/2026 | 1/9/2026 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e. | |
| Aplazada | Media (5.5) | 0.15% | — | Samsung MtowerAI | 1/9/2026 | 1/9/2026 | NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a. | |
| Modificada | Alta (7.5) | 1.0% | — | Samsung Mtower | 16/9/2022 | 17/6/2026 | A Memory Allocation with Excessive Size Value vulnerablity in the TEE_Realloc function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_Realloc with an excessive number for the parameter len. | |
| Modificada | Alta (7.5) | 1.7% | — | Samsung Mtower | 16/9/2022 | 17/6/2026 | The function tee_obj_free in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_AllocateOperation with a disturbed heap layout, related to utee_cryp_obj_alloc. | |
| Modificada | Alta (7.5) | 1.4% | — | Samsung Mtower | 16/9/2022 | 17/6/2026 | A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACUpdate with an excessive size value of chunkSize. | |
| Modificada | Alta (7.5) | 1.0% | — | Samsung Mtower | 16/9/2022 | 17/6/2026 | A NULL pointer dereference issue in the TEE_MACCompareFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACCompareFinal with a NULL pointer for the parameter operation. | |
| Modificada | Alta (7.5) | 1.0% | — | Samsung Mtower | 16/9/2022 | 17/6/2026 | A Buffer Access with Incorrect Length Value vulnerablity in the TEE_CipherUpdate function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_CipherUpdate with an excessive size value of srcLen. | |
| Modificada | Alta (7.5) | 1.0% | — | Samsung Mtower | 16/9/2022 | 17/6/2026 | A Buffer Access with Incorrect Length Value vulnerablity in the TEE_MACComputeFinal function in Samsung mTower through 0.3.0 allows a trusted application to trigger a Denial of Service (DoS) by invoking the function TEE_MACComputeFinal with an excessive size value of messageLen. | |
| Modificada | Alta (7.5) | 1.3% | — | Samsung Mtower | 5/9/2022 | 17/6/2026 | sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_public_key_affine_coordinates, leading to a denial of service. | |
| Modificada | Alta (7.5) | 1.3% | — | Samsung Mtower | 5/9/2022 | 17/6/2026 | There is a NULL pointer dereference in aes256_encrypt in Samsung mTower through 0.3.0 due to a missing check on the return value of EVP_CIPHER_CTX_new. | |
| Modificada | Alta (7.5) | 1.3% | — | Samsung Mtower | 5/9/2022 | 17/6/2026 | sign_pFwInfo in Samsung mTower through 0.3.0 has a missing check on the return value of EC_KEY_set_private_key, leading to a denial of service. | |
| Modificada | Alta (7.5) | 1.4% | — | Samsung Mtower | 1/9/2022 | 17/6/2026 | Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_GetObjectInfo1. | |
| Modificada | Alta (7.5) | 1.3% | — | Samsung Mtower | 1/9/2022 | 17/6/2026 | Samsung Electronics mTower v0.3.0 and earlier was discovered to contain a NULL pointer dereference via the function TEE_AllocateTransientObject. | |
| Modificada | Alta (7.5) | 1.0% | — | Samsung Mtower | 11/8/2022 | 17/6/2026 | TEE_Malloc in Samsung mTower through 0.3.0 allows a trusted application to achieve Excessive Memory Allocation via a large len value, as demonstrated by a Numaker-PFM-M2351 TEE kernel crash. | |
| Modificada | Alta (7.8) | 0.40% | — | Samsung Mtower | 4/8/2022 | 17/6/2026 | The TEE_PopulateTransientObject and __utee_from_attr functions in Samsung mTower 0.3.0 allow a trusted application to trigger a memory overwrite, denial of service, and information disclosure by invoking the function TEE_PopulateTransientObject with a large number in the parameter attrCount. |