Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.72% | — | GNU Grub2 | 29/12/2024 | 17/6/2026 | GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem. | |
| Aplazada | Alta (7) | 0.32% | — | GNU Grub2AI | 13/11/2024 | 17/6/2026 | grub2 allowed attackers with access to the grub shell to access files on the encrypted disks. | |
| Analizada | Media (6.7) | 0.38% | — | GNU Grub2Netapp Bootstrap OS | 5/4/2024 | 17/6/2026 | GRUB2 does not call the module fini functions on exit, leading to Debian/Ubuntu's peimage GRUB2 module leaving UEFI system table hooks after exit. This lead to a use-after-free condition, and could possibly lead to secure boot bypass. | |
| Modificada | Baja (3.3) | 0.27% | — | GNU Grub2Redhat Enterprise LinuxFedoraproject Fedora | 6/2/2024 | 17/6/2026 | A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the temporary file will not be removed and may… | |
| Modificada | Media (6.8) | 0.54% | — | GNU Grub2Redhat Enterprise LinuxFedoraproject Fedora | 15/1/2024 | 17/6/2026 | An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a… | |
| Modificada | Media (4.6) | 0.49% | — | GNU Grub2Redhat Enterprise Linux | 25/10/2023 | 21/7/2026 | An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting… | |
| Modificada | Alta (7.8) | 0.54% | — | GNU Grub2Redhat Enterprise Linux | 25/10/2023 | 21/7/2026 | An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code… | |
| Modificada | Alta (7.8) | 0.29% | — | GNU Grub2 | 20/7/2023 | 17/6/2026 | There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up operating systems that doesn't support multiboot and do not have direct support from GRUB2. When executing chainloader more than once a use-after-free vulnerability is triggered. If an attacker can… | |
| Modificada | Alta (7.8) | 0.31% | — | GNU Grub2 | 20/7/2023 | 17/6/2026 | The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to unverified code and modules to be loaded in GRUB2 breaking the secure boot trust-chain. | |
| Modificada | Alta (7) | 1.1% | — | GNU Grub2Netapp Active IQ Unified Manager | 20/7/2023 | 17/6/2026 | Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer point by one position. This can lead to a out-of-bound write further when parsing the HTTP request, writing a NULL byte past the buffer. It's conceivable that an attacker… | |
| Modificada | Alta (8.1) | 1.3% | — | GNU Grub2 | 20/7/2023 | 17/6/2026 | Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() function on rsm->total_len value. Under certain circumstances the total_len value may end up wrapping around to a small integer number which will be used in memory allocation.… | |
| Modificada | Alta (7.1) | 1.0% | — | GNU Grub2Redhat Enterprise Linux | 19/12/2022 | 17/6/2026 | When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and availability issues.… | |
| Modificada | Alta (8.6) | 0.51% | — | GNU Grub2Fedoraproject FedoraRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Power Little Endian EUS+4 | 14/12/2022 | 17/6/2026 | A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this… | |
| Modificada | Alta (7) | 0.46% | — | GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+8 | 6/7/2022 | 17/6/2026 | A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data… | |
| Modificada | Media (4.5) | 0.47% | — | GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+9 | 6/7/2022 | 17/6/2026 | A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman… | |
| Modificada | Media (4.5) | 0.46% | — | GNU Grub2Fedoraproject FedoraRedhat Developer ToolsRedhat Openshift+10 | 6/7/2022 | 17/6/2026 | A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform… | |
| Modificada | Media (4.4) | 0.24% | — | GNU Grub2 | 16/3/2022 | 17/6/2026 | A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory allows local attackers to truncate arbitrary files. This issue affects: SUSE Linux Enterprise Server 15 SP4 grub2 versions prior to 2.06-150400.7.1. SUSE openSUSE Factory grub2 versions prior to… | |
| Modificada | Baja (3.3) | 0.32% | — | GNU Grub2Fedoraproject Fedora | 10/3/2022 | 17/6/2026 | A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw… | |
| Modificada | Media (6.4) | 0.47% | — | GNU Grub2 | 15/3/2021 | 17/6/2026 | If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet it could have been tampered. This flaw is a reintroduction of CVE-2020-15705 and… | |
| Modificada | Alta (8.2) | 0.60% | 💥 PoC | GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+4 | 3/3/2021 | 17/6/2026 | A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each… | |
| Modificada | Media (6.7) | 1.0% | — | GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+4 | 3/3/2021 | 17/6/2026 | A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as… | |
| Modificada | Alta (7.5) | 0.39% | — | GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+4 | 3/3/2021 | 17/6/2026 | A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this… | |
| Modificada | Media (6.7) | 0.57% | — | GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+4 | 3/3/2021 | 17/6/2026 | A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporary storage, without sufficient bounds checking. If the function is called with a command line that references a variable… | |
| Modificada | Alta (7.6) | 0.79% | — | GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+4 | 3/3/2021 | 17/6/2026 | A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of… | |
| Modificada | Alta (8.2) | 1.2% | 💥 PoC | GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+4 | 3/3/2021 | 17/6/2026 | A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections.… |