Filtered by vendor Denx
Subscribe
Search
Total
11 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-33103 | 1 Denx | 1 U-boot | 2022-07-15 | 4.6 MEDIUM | 7.8 HIGH |
| Das U-Boot from v2020.10 to v2022.07-rc3 was discovered to contain an out-of-bounds write via the function sqfs_readdir(). | |||||
| CVE-2022-30790 | 1 Denx | 1 U-boot | 2022-06-16 | 7.2 HIGH | 7.8 HIGH |
| Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552. | |||||
| CVE-2019-13104 | 1 Denx | 1 U-boot | 2021-07-21 | 6.8 MEDIUM | 7.8 HIGH |
| In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem. | |||||
| CVE-2020-10648 | 2 Denx, Opensuse | 2 U-boot, Leap | 2021-03-26 | 6.8 MEDIUM | 7.8 HIGH |
| Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration. | |||||
| CVE-2021-27138 | 1 Denx | 1 U-boot | 2021-02-24 | 6.8 MEDIUM | 7.8 HIGH |
| The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT. | |||||
| CVE-2021-27097 | 1 Denx | 1 U-boot | 2021-02-23 | 6.8 MEDIUM | 7.8 HIGH |
| The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT. | |||||
| CVE-2019-13103 | 1 Denx | 1 U-boot | 2020-08-24 | 3.6 LOW | 7.1 HIGH |
| A crafted self-referential DOS partition table will cause all Das U-Boot versions through 2019.07-rc4 to infinitely recurse, causing the stack to grow infinitely and eventually either crash or overwrite other data. | |||||
| CVE-2018-18440 | 1 Denx | 1 U-boot | 2019-12-10 | 7.2 HIGH | 7.8 HIGH |
| DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled. | |||||
| CVE-2019-13106 | 1 Denx | 1 U-boot | 2019-10-01 | 8.3 HIGH | 7.8 HIGH |
| Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution. | |||||
| CVE-2019-13105 | 1 Denx | 1 U-boot | 2019-08-13 | 6.8 MEDIUM | 7.8 HIGH |
| Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem. | |||||
| CVE-2018-3968 | 1 Denx | 1 U-boot | 2019-04-02 | 4.4 MEDIUM | 7.0 HIGH |
| An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot. | |||||
