Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
denx u-boot vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2021-27097
The boot loader in Das U-Boot prior to 2021.04-rc2 mishandles a modified FIT.
Denx U-boot
Denx U-boot 2021.04
6.8
CVSSv2
CVE-2021-27138
The boot loader in Das U-Boot prior to 2021.04-rc2 mishandles use of unit addresses in a FIT.
Denx U-boot
Denx U-boot 2021.04
6.8
CVSSv2
CVE-2020-10648
Das U-Boot up to and including 2020.01 allows malicious users to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.
Denx U-boot
Denx U-boot 2020.01
Opensuse Leap 15.2
6.8
CVSSv2
CVE-2019-13105
Das U-Boot versions 2019.07-rc1 up to and including 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem.
Denx U-boot 2019.07
6.8
CVSSv2
CVE-2019-13104
In Das U-Boot versions 2016.11-rc1 up to and including 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.
Denx U-boot 2019.07
Denx U-boot
Opensuse Leap 15.0
Opensuse Leap 15.1
6.4
CVSSv2
CVE-2019-14197
An issue exists in Das U-Boot up to and including 2019.07. There is a read of out-of-bounds data at nfs_read_reply.
Denx U-boot
4.6
CVSSv2
CVE-2022-33103
Das U-Boot from v2020.10 to v2022.07-rc3 exists to contain an out-of-bounds write via the function sqfs_readdir().
Denx U-boot 2022.07
Denx U-boot
4.4
CVSSv2
CVE-2018-3968
An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an malicious user to bypass U-Boot's verified boot and execute an unsigned...
Denx U-boot 2013.07
Denx U-boot
Denx U-boot 2014.07
4.4
CVSSv2
CVE-2017-3226
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of Das U-Boot's AES-CBC encryption feature using environment encryption (i.e., setting the configuration parameter CONFIG_ENV_AES=y) read environment variables...
Denx U-boot
4.3
CVSSv2
CVE-2019-11690
gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows malicious users to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot devic...
Denx U-boot
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »