Known vulnerabilities in shim-signed (Red Hat package)
Vendor:
Red Hat Inc.
Software:
shim-signed (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:shim-signed_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
14
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (14)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU86241 - NULL Pointer Dereference CVE-2023-40546 |
CWE-476 | Medium | 15.8-1.el7 | 07.02.2024 |
SB2024020767 SB20231110100 SB20231110101 and 23 more |
||
| #VU86240 - Out-of-bounds read CVE-2023-40551 |
CWE-125 | Medium | 15.8-1.el7 | 07.02.2024 |
SB2024020767 SB20240312192 SB20240312193 and 26 more |
||
| #VU86239 - Out-of-bounds read CVE-2023-40550 |
CWE-125 | Medium | 15.8-1.el7 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 24 more |
||
| #VU86238 - Out-of-bounds read CVE-2023-40549 |
CWE-125 | Medium | 15.8-1.el7 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 24 more |
||
| #VU86237 - Integer overflow CVE-2023-40548 |
CWE-190 | Medium | 15.8-1.el7 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 23 more |
||
| #VU86236 - Insufficient Verification of Data Authenticity CVE-2023-40547 |
CWE-345 | High | 15.8-1.el7 | 07.02.2024 |
SB2024020767 SB20240312192 SB20240312193 and 27 more |
||
| #VU32936 - Integer overflow CVE-2020-14311 |
CWE-190 | Low | 15-7.el7_8, 15-8.el7_2, 15-8.el7_7 | 30.07.2020 |
SB2020073018 SB2020073035 SB2020073036 and 17 more |
||
| #VU32935 - Integer overflow CVE-2020-14310 |
CWE-190 | Low | 15-7.el7_8, 15-8.el7_2, 15-8.el7_7 | 30.07.2020 |
SB2020073018 SB2020073035 SB2020073036 and 17 more |
||
| #VU32934 - Integer overflow CVE-2020-14309 |
CWE-190 | Low | 15-7.el7_8, 15-8.el7_2, 15-8.el7_7 | 30.07.2020 |
SB2020073018 SB2020073035 SB2020073036 and 17 more |
||
| #VU32927 - Improper Verification of Cryptographic Signature CVE-2020-15705 |
CWE-347 | Low | 15-7.el7_8, 15-8.el7_2, 15-8.el7_7 | 30.07.2020 |
SB2020073017 SB2020073035 SB2020073036 and 16 more |
||
| #VU32926 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2020-15706 |
CWE-362 | Low | 15-7.el7_8, 15-8.el7_2, 15-8.el7_7 | 30.07.2020 |
SB2020073017 SB2020073035 SB2020073036 and 17 more |
||
| #VU32925 - Integer overflow CVE-2020-15707 |
CWE-190 | Low | 15-7.el7_8, 15-8.el7_7 | 30.07.2020 |
SB2020073017 SB2020073035 SB2020073036 and 16 more |
||
| #VU32923 - Heap-based Buffer Overflow CVE-2020-14308 |
CWE-122 | Low | 15-7.el7_8, 15-8.el7_2, 15-8.el7_7 | 30.07.2020 |
SB2020073018 SB2020073035 SB2020073036 and 17 more |
||
| #VU32922 - Out-of-bounds write CVE-2020-10713 |
CWE-787 | Low | 15-7.el7_8, 15-8.el7_2, 15-8.el7_7 | 30.07.2020 |
SB2020073018 SB2020073026 SB2020073027 and 33 more |