Vulnerabilities > Redhat > Shim > High

DATE CVE VULNERABILITY TITLE RISK
2024-01-29 CVE-2023-40548 Integer Overflow or Wraparound vulnerability in multiple products
A buffer overflow was found in Shim in the 32-bit system.
local
high complexity
redhat fedoraproject CWE-190
7.4
2024-01-25 CVE-2023-40547 Out-of-bounds Write vulnerability in Redhat Enterprise Linux and Shim
A remote code execution vulnerability was found in Shim.
high complexity
redhat CWE-787
8.3
2023-07-20 CVE-2022-28737 Out-of-bounds Write vulnerability in Redhat Shim
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded.
local
low complexity
redhat CWE-787
7.8
2014-10-22 CVE-2014-3677 Unspecified vulnerability in Redhat Shim
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.
network
low complexity
redhat
7.5
2014-10-22 CVE-2014-3676 Out-Of-Bounds Write vulnerability in Redhat Shim
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."
network
low complexity
redhat CWE-787
7.5