| O3DS & O2DS SAFE_FIRM is still vulnerable to the PXIAM:ImportCertificates flaw fixed in [[5.0.0-11]] and to SSLoth fixed in [[11.14.0-46]]. It makes it possible to spoof the official NUS update server and remotely trigger the vulnerability in SAFE_FIRM.
+
| Remote Arm9 code execution in O3DS/O2DS SAFE_FIRM
+
| None
+
| [[11.14.0-46|11.14.0-X]]
+
| 2020
+
| December 18, 2020
+
| [[User:Nba_Yoh|MrNbaYoh]]
|-
|-
| twlhax: Corrupted SRL header leads to memory overwrite
| twlhax: Corrupted SRL header leads to memory overwrite