Known vulnerabilities in shim (Red Hat package)
Vendor:
Red Hat Inc.
Software:
shim (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:shim_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
29
Public exploits:
4
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
Vulnerabilities (29)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU86241 - NULL Pointer Dereference CVE-2023-40546 |
CWE-476 | Medium | 15.8-2.el8, 15.8-2.el8_2, 15.8-2.el8_4, 15.8-2.el8_6, 15.8-3.el7, 15.8-3.el9, 15.8-3.el9_2, 15.8-4.el8_9, 15.8-4.el9_3 | 07.02.2024 |
SB2024020767 SB20231110100 SB20231110101 and 23 more |
||
| #VU86240 - Out-of-bounds read CVE-2023-40551 |
CWE-125 | Medium | 15.8-2.el8, 15.8-2.el8_2, 15.8-2.el8_4, 15.8-2.el8_6, 15.8-3.el7, 15.8-3.el9, 15.8-3.el9_2, 15.8-4.el8_9, 15.8-4.el9_3 | 07.02.2024 |
SB2024020767 SB20240312192 SB20240312193 and 26 more |
||
| #VU86239 - Out-of-bounds read CVE-2023-40550 |
CWE-125 | Medium | 15.8-2.el8, 15.8-2.el8_2, 15.8-2.el8_4, 15.8-2.el8_6, 15.8-3.el7, 15.8-3.el9, 15.8-3.el9_2, 15.8-4.el8_9, 15.8-4.el9_3 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 24 more |
||
| #VU86238 - Out-of-bounds read CVE-2023-40549 |
CWE-125 | Medium | 15.8-2.el8, 15.8-2.el8_2, 15.8-2.el8_4, 15.8-2.el8_6, 15.8-3.el7, 15.8-3.el9, 15.8-3.el9_2, 15.8-4.el8_9, 15.8-4.el9_3 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 24 more |
||
| #VU86237 - Integer overflow CVE-2023-40548 |
CWE-190 | Medium | 15.8-2.el8, 15.8-2.el8_2, 15.8-2.el8_4, 15.8-2.el8_6, 15.8-3.el7, 15.8-3.el9, 15.8-3.el9_2, 15.8-4.el8_9, 15.8-4.el9_3 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 23 more |
||
| #VU86236 - Insufficient Verification of Data Authenticity CVE-2023-40547 |
CWE-345 | High | 15.8-2.el8, 15.8-2.el8_2, 15.8-2.el8_4, 15.8-2.el8_6, 15.8-3.el7, 15.8-3.el9, 15.8-3.el9_2, 15.8-4.el8_9, 15.8-4.el9_3 | 07.02.2024 |
SB2024020767 SB20240312192 SB20240312193 and 27 more |
||
| #VU64067 - Out-of-bounds write CVE-2022-28737 |
CWE-787 | Low | 15.6-1.el8, 15.6-1.el9 | 08.06.2022 |
SB2022060810 SB2022061652 SB2022061653 and 24 more |
||
| #VU64065 - Use After Free CVE-2022-28736 |
CWE-416 | Low | 15.6-1.el8, 15.6-1.el9 | 08.06.2022 |
SB2022060810 SB2022061540 SB2022061566 and 32 more |
||
| #VU64064 - Insufficient Verification of Data Authenticity CVE-2022-28735 |
CWE-345 | Low | 15.6-1.el8, 15.6-1.el9 | 08.06.2022 |
SB2022060810 SB2022061540 SB2022061566 and 24 more |
||
| #VU64063 - Out-of-bounds write CVE-2022-28734 |
CWE-787 | Medium | 15.6-1.el8, 15.6-1.el9 | 08.06.2022 |
SB2022060810 SB2022061540 SB2022061566 and 36 more |
||
| #VU64062 - Integer underflow CVE-2022-28733 |
CWE-191 | High | 15.6-1.el8, 15.6-1.el9 | 08.06.2022 |
SB2022060810 SB2022061540 SB2022061566 and 38 more |
||
| #VU64061 - Integer underflow CVE-2021-3697 |
CWE-191 | Low | 15.6-1.el8, 15.6-1.el9 | 08.06.2022 |
SB2022060810 SB2022061540 SB2022061566 and 31 more |
||
| #VU64059 - Out-of-bounds write CVE-2021-3696 |
CWE-787 | Low | 15.6-1.el8, 15.6-1.el9 | 08.06.2022 |
SB2022060810 SB2022061540 SB2022061566 and 31 more |
||
| #VU64057 - Out-of-bounds write CVE-2021-3695 |
CWE-787 | Low | 15.6-1.el8, 15.6-1.el9 | 08.06.2022 |
SB2022060810 SB2022061540 SB2022061566 and 31 more |
||
| #VU51198 - Out-of-bounds write CVE-2021-20233 |
CWE-787 | Low | 15.4-2.el8_1 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
||
| #VU51197 - Out-of-bounds write CVE-2021-20225 |
CWE-787 | Low | 15.4-2.el8_1 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
||
| #VU51194 - Improper Authorization CVE-2020-27779 |
CWE-285 | Low | 15.4-2.el8_1 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
||
| #VU51193 - Stack-based buffer overflow CVE-2020-27749 |
CWE-121 | Low | 15.4-2.el8_1 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
||
| #VU51189 - Out-of-bounds write CVE-2020-25647 |
CWE-787 | Low | 15.4-2.el8_1 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 35 more |
||
| #VU51188 - Use After Free CVE-2020-25632 |
CWE-416 | Low | 15.4-2.el8_1 | 03.03.2021 |
SB2021030311 SB2021030401 SB2021030402 and 37 more |
Showing elements 1 - 20 out of 29