Known vulnerabilities in shim
Vendor:
openEuler
Software:
shim
Software CPE:
cpe:2.3:o:openeuler:shim:*:*:*:*:*:openeuler:*:*
Website:
https://www.openeuler.org/
Total vulnerabilities:
24
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (24)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU134270 - Use After Free CVE-2026-45447 |
CWE-416 | High | 15.7-27 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 48 more |
||
| #VU134276 - Heap-based Buffer Overflow CVE-2026-7383 |
CWE-122 | Low | 15.7-27 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 35 more |
||
| #VU134278 - Out-of-bounds read CVE-2026-34180 |
CWE-125 | Medium | 15.7-27 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 36 more |
||
| #VU125565 - NULL Pointer Dereference CVE-2026-28388 |
CWE-476 | Low | 15.6-30, 15.7-26, 15-41 | 09.04.2026 |
SB2026040943 SB2026040944 SB2026040945 and 39 more |
||
| #VU122084 - NULL Pointer Dereference CVE-2025-69421 |
CWE-476 | Medium | 15.6-27 | 27.01.2026 |
SB2026012785 SB2026012791 SB2026012792 and 50 more |
||
| #VU86241 - NULL Pointer Dereference CVE-2023-40546 |
CWE-476 | Medium | 15.4-10, 15.6-12 | 07.02.2024 |
SB2024020767 SB20231110100 SB20231110101 and 23 more |
||
| #VU86240 - Out-of-bounds read CVE-2023-40551 |
CWE-125 | Medium | 15.4-13, 15.6-16, 15.6-17, 15.6-19, 15-28, 15-34 | 07.02.2024 |
SB2024020767 SB20240312192 SB20240312193 and 26 more |
||
| #VU86239 - Out-of-bounds read CVE-2023-40550 |
CWE-125 | Medium | 15.4-13, 15.6-16, 15.6-17, 15.6-19 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 24 more |
||
| #VU86238 - Out-of-bounds read CVE-2023-40549 |
CWE-125 | Medium | 15.4-13, 15.6-16, 15.6-17, 15.6-19 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 24 more |
||
| #VU86237 - Integer overflow CVE-2023-40548 |
CWE-190 | Medium | 15.4-13, 15.6-16, 15.6-17, 15.6-19 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 23 more |
||
| #VU86236 - Insufficient Verification of Data Authenticity CVE-2023-40547 |
CWE-345 | High | 15.4-13, 15.6-16, 15.6-17, 15.6-19, 15-28, 15-34 | 07.02.2024 |
SB2024020767 SB20240312192 SB20240312193 and 27 more |
||
| #VU85808 - NULL Pointer Dereference CVE-2024-0727 |
CWE-476 | Medium | 15.4-14, 15.6-17, 15.6-18, 15.6-20 | 25.01.2024 |
SB2024012552 SB2024020525 SB2024021323 and 100 more |
||
| #VU78463 - Resource Management Errors CVE-2023-3446 |
CWE-399 | Medium | 15.4-14, 15.6-17, 15.6-18, 15-29, 15-35 | 20.07.2023 |
SB2023072079 SB2023072524 SB2023072525 and 152 more |
||
| #VU76651 - Resource Management Errors CVE-2023-2650 |
CWE-399 | Medium | 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35 | 30.05.2023 |
SB2023053040 SB2023053044 SB2023053045 and 131 more |
||
| #VU74148 - Improper Verification of Cryptographic Signature CVE-2023-0465 |
CWE-347 | Low | 15.4-14, 15.6-17, 15.6-18, 15.6-20, 15-29, 15-35 | 28.03.2023 |
SB2023032241 SB2023040666 SB2023040730 and 100 more |
||
| #VU73960 - Resource exhaustion CVE-2023-0464 |
CWE-400 | Medium | 15.4-13, 15.6-16, 15.6-17, 15-28 | 22.03.2023 |
SB2023032241 SB2023033057 SB2023033058 and 100 more |
||
| #VU71992 - Type confusion CVE-2023-0286 |
CWE-843 | High | 15-26 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 223 more |
||
| #VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-0778 |
CWE-835 | Medium | 15-23 | 15.03.2022 |
SB2022031520 SB2022031522 SB2022031611 and 238 more |
||
| #VU56064 - Out-of-bounds read CVE-2021-3712 |
CWE-125 | Medium | 15-23 | 24.08.2021 |
SB2021082414 SB2021082508 SB2021082510 and 142 more |
||
| #VU13325 - Improper input validation CVE-2018-0732 |
CWE-20 | Low | 15-23 | 12.06.2018 |
SB2018061305 SB2018070906 SB2018073005 and 54 more |
Showing elements 1 - 20 out of 24