Записи denx
50 опубликованных записей вендора denx.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 80 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-787 Out-of-bounds Write15
- CWE-191 Integer Underflow (Wrap or Wraparound)4
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')4
- CWE-190 Integer Overflow or Wraparound4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-329 Generation of Predictable IV with CBC Mode2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
50 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-8432Эксплойта нет | In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function.denx · u-boot · CWE-415 | Критическая9,8 | — | 3,1 % | 29 янв. 2020 г. |
40В плане | CVE-2019-14192Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-191 | Критическая9,8 | — | 2,8 % | 31 июл. 2019 г. |
40В плане | CVE-2022-30767Эксплойта нет | nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, ledenx · u-boot · CWE-120 | Критическая9,8 | — | 2,7 % | 15 мая 2022 г. |
40В плане | CVE-2019-14204Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-787 | Критическая9,8 | — | 2,7 % | 31 июл. 2019 г. |
40В плане | CVE-2019-14202Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-787 | Критическая9,8 | — | 2,6 % | 31 июл. 2019 г. |
40В плане | CVE-2019-14203Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-787 | Критическая9,8 | — | 2,6 % | 31 июл. 2019 г. |
40В плане | CVE-2019-14200Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-787 | Критическая9,8 | — | 2,6 % | 31 июл. 2019 г. |
40В плане | CVE-2019-14201Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-787 | Критическая9,8 | — | 2,6 % | 31 июл. 2019 г. |
40В плане | CVE-2019-14193Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-787 | Критическая9,8 | — | 2,6 % | 31 июл. 2019 г. |
40В плане | CVE-2019-14195Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-787 | Критическая9,8 | — | 2,5 % | 31 июл. 2019 г. |
40В плане | CVE-2019-14198Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-787 | Критическая9,8 | — | 2,4 % | 31 июл. 2019 г. |
40В плане | CVE-2019-14199Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-191 | Критическая9,8 | — | 2,4 % | 31 июл. 2019 г. |
40В плане | CVE-2019-14194Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-787 | Критическая9,8 | — | 2,4 % | 31 июл. 2019 г. |
40В плане | CVE-2022-34835Эксплойта нет | In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables thedenx · u-boot · CWE-787 | Критическая9,8 | — | 2,2 % | 29 июн. 2022 г. |
40В плане | CVE-2019-14196Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-787 | Критическая9,8 | — | 2,1 % | 31 июл. 2019 г. |
40В плане | CVE-2018-18439Эксплойта нет | DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled.denx · u-boot · CWE-119 | Критическая9,8 | — | 2,0 % | 20 нояб. 2018 г. |
40В плане | CVE-2019-11059Эксплойта нет | Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.denx · u-boot · CWE-119 | Критическая9,8 | — | 1,9 % | 10 мая 2019 г. |
37Наблюдать | CVE-2019-14197Эксплойта нет | An issue was discovered in Das U-Boot through 2019.07.denx · u-boot · CWE-125 | Критическая9,1 | — | 2,5 % | 31 июл. 2019 г. |
35Наблюдать | CVE-2026-29009Эксплойта нет | U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINKdenx · u-boot · CWE-120 | Высокая8,8 | — | 0,7 % | 8 июл. 2026 г. |
35Наблюдать | CVE-2026-46728Эксплойта нет | Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.denx · u-boot · CWE-346 | Высокая8,8 | — | 0,1 % | 16 мая 2026 г. |
34Наблюдать | CVE-2026-29008Эксплойта нет | U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()denx · u-boot · CWE-191 | Высокая8,7 | — | 0,7 % | 8 июл. 2026 г. |
32Наблюдать | CVE-2019-13106Эксплойта нет | Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stackdenx · u-boot · CWE-787 | Высокая7,8 | — | 1,8 % | 6 авг. 2019 г. |
32Наблюдать | CVE-2024-42040Эксплойта нет | Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allowdenx · u-boot · CWE-120 | Высокая8,1 | — | 0,6 % | 23 авг. 2024 г. |
31Наблюдать | CVE-2020-10648Эксплойта нет | Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a craftdenx · u-boot · CWE-20 | Высокая7,8 | — | 1,4 % | 19 мар. 2020 г. |
31Наблюдать | CVE-2019-13105Эксплойта нет | Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem.denx · u-boot · CWE-415 | Высокая7,8 | — | 1,3 % | 6 авг. 2019 г. |
- CVE-2020-843240В плане
In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot29 янв. 2020 г.
- CVE-2019-1419240В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot31 июл. 2019 г.
- CVE-2022-3076740В плане
nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, le
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot15 мая 2022 г.
- CVE-2019-1420440В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot31 июл. 2019 г.
- CVE-2019-1420240В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot31 июл. 2019 г.
- CVE-2019-1420340В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot31 июл. 2019 г.
- CVE-2019-1420040В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot31 июл. 2019 г.
- CVE-2019-1420140В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot31 июл. 2019 г.
- CVE-2019-1419340В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot31 июл. 2019 г.
- CVE-2019-1419540В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %denx · u-boot31 июл. 2019 г.
- CVE-2019-1419840В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %denx · u-boot31 июл. 2019 г.
- CVE-2019-1419940В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %denx · u-boot31 июл. 2019 г.
- CVE-2019-1419440В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %denx · u-boot31 июл. 2019 г.
- CVE-2022-3483540В плане
In Das U-Boot through 2022.07-rc5, an integer signedness error and resultant stack-based buffer overflow in the "i2c md" command enables the
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %denx · u-boot29 июн. 2022 г.
- CVE-2019-1419640В плане
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %denx · u-boot31 июл. 2019 г.
- CVE-2018-1843940В плане
DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %denx · u-boot20 нояб. 2018 г.
- CVE-2019-1105940В плане
Das U-Boot 2016.11-rc1 through 2019.04 mishandles the ext4 64-bit extension, resulting in a buffer overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %denx · u-boot10 мая 2019 г.
- CVE-2019-1419737Наблюдать
An issue was discovered in Das U-Boot through 2019.07.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %denx · u-boot31 июл. 2019 г.
- CVE-2026-2900935Наблюдать
U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %denx · u-boot8 июл. 2026 г.
- CVE-2026-4672835Наблюдать
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %denx · u-boot16 мая 2026 г.
- CVE-2026-2900834Наблюдать
U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %denx · u-boot8 июл. 2026 г.
- CVE-2019-1310632Наблюдать
Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %denx · u-boot6 авг. 2019 г.
- CVE-2024-4204032Наблюдать
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allow
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %denx · u-boot23 авг. 2024 г.
- CVE-2020-1064831Наблюдать
Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a craft
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %denx · u-boot19 мар. 2020 г.
- CVE-2019-1310531Наблюдать
Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %denx · u-boot6 авг. 2019 г.