Vulnerabilities > Denx > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-06-08 CVE-2022-30552 Classic Buffer Overflow vulnerability in Denx U-Boot 2022.01
Das U-Boot 2022.01 has a Buffer Overflow.
local
low complexity
denx CWE-120
5.5
2019-05-03 CVE-2019-11690 Use of Insufficiently Random Values vulnerability in Denx U-Boot
gen_rand_uuid in lib/uuid.c in Das U-Boot v2014.04 through v2019.04 lacks an srand call, which allows attackers to determine UUID values in scenarios where CONFIG_RANDOM_UUID is enabled, and Das U-Boot is relied upon for UUID values of a GUID Partition Table of a boot device.
network
high complexity
denx CWE-330
5.9
2018-07-24 CVE-2017-3226 Cryptographic Issues vulnerability in Denx U-Boot
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file.
high complexity
denx CWE-310
6.4
2018-07-24 CVE-2017-3225 Cryptographic Issues vulnerability in Denx U-Boot
Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file.
low complexity
denx CWE-310
4.6
2018-06-26 CVE-2018-1000205 Improper Input Validation vulnerability in Denx U-Boot
U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot.
local
low complexity
denx CWE-20
5.5