Vulnerabilities > Redhat > Shim > 0.3

DATE CVE VULNERABILITY TITLE RISK
2023-07-20 CVE-2022-28737 Out-of-bounds Write vulnerability in Redhat Shim
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded.
local
low complexity
redhat CWE-787
7.8
2014-10-22 CVE-2014-3677 Unspecified vulnerability in Redhat Shim
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
network
low complexity
redhat
7.5
2014-10-22 CVE-2014-3676 Out-Of-Bounds Write vulnerability in Redhat Shim
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."
network
low complexity
redhat CWE-787
7.5
2014-10-22 CVE-2014-3675 Out-Of-Bounds Read vulnerability in Redhat Shim
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.
network
low complexity
redhat CWE-125
5.0