Lucene search

K

Ti Security Vulnerabilities

cve
cve

CVE-2022-25332

The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM, suffers from a timing side channel which can be exploited by an adversary with non-secure supervisor privileges by managing cache contents and collecting timing information for different ciphertext...

4.4CVSS

5.7AI Score

0.0004EPSS

2023-10-19 10:15 AM
28
cve
cve

CVE-2021-27502

Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-11-21 06:15 PM
11
cve
cve

CVE-2021-27429

Texas Instruments TI-RTOS returns a valid pointer to a small buffer on extremely large values. This can trigger an integer overflow vulnerability in 'HeapTrack_alloc' and result in code...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-11-20 07:15 PM
5
cve
cve

CVE-2021-22636

Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'HeapMem_allocUnprotected' and result in code...

7.8CVSS

7.9AI Score

0.0004EPSS

2023-11-20 07:15 PM
9
cve
cve

CVE-2021-27504

Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values, which can trigger an integer overflow vulnerability in 'malloc' for FreeRTOS, resulting in code...

7.8CVSS

8AI Score

0.0004EPSS

2023-11-21 06:15 PM
11
cve
cve

CVE-2022-25334

The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) lacks a bounds check on the signature size field in the SK_LOAD module loading routine, present in mask ROM. A module with a sufficiently large signature field causes a stack overflow, affecting secure kernel...

8.8CVSS

6.5AI Score

0.0004EPSS

2023-10-19 10:15 AM
18
cve
cve

CVE-2022-25333

The Texas Instruments OMAP L138 (secure variants) trusted execution environment (TEE) performs an RSA check implemented in mask ROM when loading a module through the SK_LOAD routine. However, only the module header authenticity is validated. An adversary can re-use any correctly signed header and.....

8.8CVSS

6.7AI Score

0.0004EPSS

2023-10-19 10:15 AM
21
cve
cve

CVE-2023-29468

The Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EXT_2_IE_ID that can be parsed in a management frame. Using a specially crafted frame, a buffer overflow can be triggered that can potentially lead to remote...

9.8CVSS

9.8AI Score

0.003EPSS

2023-08-14 07:15 PM
32
cve
cve

CVE-2021-21966

An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 SimpleLink Solution NWP 2.9.0.0. A specially-crafted HTTP request can lead to an uninitialized read. An attacker can send an HTTP request to trigger this...

5.3CVSS

5AI Score

0.003EPSS

2022-02-16 05:15 PM
39
2
cve
cve

CVE-2020-16630

TI’s BLE stack caches and reuses the LTK’s property for a bonded mobile. A LTK can be an unauthenticated-and-no-MITM-protection key created by Just Works or an authenticated-and-MITM-protection key created by Passkey Entry, Numeric Comparison or OOB. Assume that a victim mobile uses secure pairing....

6.8CVSS

6.5AI Score

0.001EPSS

2021-09-20 08:15 PM
21
cve
cve

CVE-2021-34149

The Bluetooth Classic implementation on the Texas Instruments CC256XCQFN-EM does not properly handle the reception of continuous LMP_AU_Rand packets, allowing attackers in radio range to trigger a denial of service (deadlock) of the device by flooding it with LMP_AU_Rand packets after the paging...

6.5CVSS

6.3AI Score

0.001EPSS

2021-09-07 07:15 AM
22
cve
cve

CVE-2021-22677

An integer overflow exists in the APIs of the host MCU while trying to connect to a WIFI network may lead to issues such as a denial-of-service condition or code execution on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to...

7.8CVSS

7.9AI Score

0.0004EPSS

2021-05-07 04:15 PM
27
3
cve
cve

CVE-2021-22671

Multiple integer overflow issues exist while processing long domain names, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK versions...

9.8CVSS

9.6AI Score

0.003EPSS

2021-05-07 02:15 PM
29
2
cve
cve

CVE-2021-22673

The affected product is vulnerable to stack-based buffer overflow while processing over-the-air firmware updates from the CDN server, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK...

8CVSS

8.1AI Score

0.001EPSS

2021-05-07 02:15 PM
22
2
cve
cve

CVE-2021-22675

The affected product is vulnerable to integer overflow while parsing malformed over-the-air firmware update files, which may allow an attacker to remotely execute code on SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03,....

7.2CVSS

7.2AI Score

0.001EPSS

2021-05-07 01:15 PM
25
2
cve
cve

CVE-2021-22679

The affected product is vulnerable to an integer overflow while processing HTTP headers, which may allow an attacker to remotely execute code on the SimpleLink Wi-Fi (MSP432E4 SDK: v4.20.00.12 and prior, CC32XX SDK v4.30.00.06 and prior, CC13X0 SDK versions prior to v4.10.03, CC13X2 and CC26XX SDK....

9.8CVSS

9.5AI Score

0.003EPSS

2021-05-07 01:15 PM
22
2
cve
cve

CVE-2021-3285

jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for...

5.3CVSS

6.4AI Score

0.001EPSS

2021-01-26 06:16 PM
28
6
cve
cve

CVE-2020-27892

The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Discover Commands Received Response message or a ZCL Discover Commands Generated Response message. It crashes in...

7.5CVSS

7.5AI Score

0.001EPSS

2020-10-27 09:15 PM
38
cve
cve

CVE-2020-27890

The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Write Attributes No Response message. It crashes in zclParseInWriteCmd() and does not update the specific attribute's...

8.2CVSS

8.1AI Score

0.001EPSS

2020-10-27 09:15 PM
24
cve
cve

CVE-2020-27891

The Zigbee protocol implementation on Texas Instruments CC2538 devices with Z-Stack 3.0.1 does not properly process a ZCL Read Reporting Configuration Response message. It crashes in...

7.5CVSS

7.5AI Score

0.001EPSS

2020-10-27 09:15 PM
31
cve
cve

CVE-2020-13593

The Bluetooth Low Energy Secure Manager Protocol (SMP) implementation in Texas Instruments SimpleLink SIMPLELINK-CC2640R2-SDK through 2.2.3 allows the Diffie-Hellman check during the Secure Connection pairing to be skipped if the Link Layer encryption setup is performed earlier. An attacker in...

8.8CVSS

8.8AI Score

0.001EPSS

2020-08-31 03:15 PM
22
cve
cve

CVE-2019-19193

The Bluetooth Low Energy peripheral implementation on Texas Instruments SIMPLELINK-CC2640R2-SDK through 3.30.00.20 and BLE-STACK through 1.5.0 before Q4 2019 for CC2640R2 and CC2540/1 devices does not properly restrict the advertisement connection request packet on reception, allowing attackers in....

6.5CVSS

6.4AI Score

0.001EPSS

2020-02-10 09:51 PM
57
cve
cve

CVE-2019-17520

The Bluetooth Low Energy implementation on Texas Instruments SDK through 3.30.00.20 for CC2640R2 devices does not properly restrict the SM Public Key packet on reception, allowing attackers in radio range to cause a denial of service (crash) via crafted...

6.5CVSS

6.6AI Score

0.001EPSS

2020-02-10 09:51 PM
41
cve
cve

CVE-2013-6239

Cross-site scripting (XSS) vulnerability in the photo gallery model in Exis Contexis before 2.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter in a detail...

6.1CVSS

6AI Score

0.005EPSS

2019-11-22 07:15 PM
78
cve
cve

CVE-2019-15948

Texas Instruments CC256x and WL18xx dual-mode Bluetooth controller devices, when LE scan mode is used, allow remote attackers to trigger a buffer overflow via a malformed Bluetooth Low Energy advertising packet, to cause a denial of service or potentially execute arbitrary code. This affects...

8.8CVSS

9AI Score

0.01EPSS

2019-11-13 04:15 PM
28
cve
cve

CVE-2018-18056

An issue was discovered in the Texas Instruments (TI) TM4C, MSP432E and MSP432P microcontroller series. The eXecute-Only-Memory (XOM) implementation prevents code read-outs on protected memory by generating bus faults. However, single-stepping and using breakpoints is allowed in XOM-protected...

4.6CVSS

5.1AI Score

0.001EPSS

2019-08-20 05:15 PM
27
cve
cve

CVE-2018-16986

Texas Instruments BLE-STACK v2.2.1 for SimpleLink CC2640 and CC2650 devices allows remote attackers to execute arbitrary code via a malformed packet that triggers a buffer...

8.8CVSS

8.6AI Score

0.05EPSS

2018-11-06 04:00 PM
35
cve
cve

CVE-2008-4994

The (1) ncsarmt and (2) ncsawrap scripts in xmcd 2.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.*pid temporary...

6.3AI Score

0.0004EPSS

2008-11-07 07:36 PM
25
4
cve
cve

CVE-2006-2542

xmcdconfig in xmcd for Debian GNU/Linux 2.6-17.1 creates /var/lib/cddb and /var/lib/xmcd/discog with world writable permissions, which allows local users to cause a denial of service (disk...

6.1AI Score

0.0004EPSS

2006-05-23 10:06 AM
26
cve
cve

CVE-2001-1119

cda in xmcd 3.0.2 and 2.6 in SuSE Linux allows local users to overwrite arbitrary files via a symlink...

6.4AI Score

0.0004EPSS

2002-06-25 04:00 AM
19