Arm Trusted Firmware Project maintains a focused, foundational firmware component that executes at the highest privilege level across Arm-based systems, from embedded devices to servers. Its narrow but critical exposure concentrates on the Arm Trusted Firmware product itself and recurs through integer-overflow and wraparound weaknesses typical of low-level code handling memory and privilege boundaries. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Arm Trusted Firmware Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10319MEDIUM In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects cer | Apr 6, 2017 | 5.9 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Arm Trusted Firmware Project.
Media articles that mention a CVE ID that affects a product developed by Arm Trusted Firmware Project — matched by CVE ID, not by vendor name.