Comparison Overview
Onto Innovation

Onto Innovation
16 Jonspin Rd, Wilmington, 01887, US
Last Update: 06/02/2026
Onto Innovation is a leader in process control, combining global scale with an expanded portfolio of leading-edge technologies that include: Un-patterned wafer quality; 3D metrology spanning chip features from nanometer scale transistors to large die interconnects; macr...

Arm
110 Fulbourn Road, Cambridge, Cambs, GB, CB1 9NJ
Last Update: 20/09/2026
Arm’s foundational technology is defining the future of computing. A future built by the greatest technology ecosystem in the world. A future built on Arm. Arm is everywhere technology matters. Technology matters everywhere. Together, we’ll power every technology revo...
Compliance Ranges Comparison

Onto Innovation







Arm






Benchmark & Cyber Underwriting Signals
Incidents vs Semiconductor Manufacturing Industry Avg (This Year)
No incidents recorded for Onto Innovation in 2026.
Incidents vs Semiconductor Manufacturing Industry Avg (This Year)
No incidents recorded for Arm in 2026.
Incident History - Onto Innovation (X = Date, Y = Severity)
Onto Innovation cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Arm (X = Date, Y = Severity)
Arm cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Onto Innovation

Arm
FAQ
Latest Global CVEs
Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.
Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.
Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.
Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes arbitrary shell commands with the privileges of the user running Vibe.
- https://github.com/mistralai/mistral-vibe
- https://github.com/mistralai/mistral-vibe/blob/19b5b74faa78d0816b8d4d4c7d7543fc3520678c/vibe/core/git/repo.py#L411-L431
- https://github.com/mistralai/mistral-vibe/commit/c069ffa1e12fb5f2487b489217c40ab97721d553
- https://github.com/mistralai/mistral-vibe/issues/996
- https://github.com/mistralai/mistral-vibe/releases/tag/v2.25.5
- https://www.vulncheck.com/advisories/mistral-vibe-before-2.25.5-remote-code-execution-via-git-post-checkout