Known vulnerabilities in Shim 12
Vendor:
Red Hat Bootloader Team
Software:
Shim
Version:
12
Software CPE:
cpe:2.3:a:rhboot:shim:*:*:*:*:*:*:*:*
Website:
https://github.com/rhboot/
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Vulnerabilities by Severity
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU86241 - NULL Pointer Dereference CVE-2023-40546 |
CWE-476 | Medium | 15.8 | 07.02.2024 |
SB2024020767 SB20231110100 SB20231110101 and 23 more |
||
| #VU86240 - Out-of-bounds read CVE-2023-40551 |
CWE-125 | Medium | 15.8 | 07.02.2024 |
SB2024020767 SB20240312192 SB20240312193 and 26 more |
||
| #VU86239 - Out-of-bounds read CVE-2023-40550 |
CWE-125 | Medium | 15.8 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 24 more |
||
| #VU86238 - Out-of-bounds read CVE-2023-40549 |
CWE-125 | Medium | 15.8 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 24 more |
||
| #VU86237 - Integer overflow CVE-2023-40548 |
CWE-190 | Medium | 15.8 | 07.02.2024 |
SB2024020767 SB20240312193 SB20240312194 and 23 more |
||
| #VU86236 - Insufficient Verification of Data Authenticity CVE-2023-40547 |
CWE-345 | High | 15.8 | 07.02.2024 |
SB2024020767 SB20240312192 SB20240312193 and 27 more |