Vulnerabilities
Vulnerable Software
Gnu:  Security Vulnerabilities
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.
CVSS Score
5.7
EPSS Score
0.0
Published
2020-07-29
GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.
CVSS Score
6.5
EPSS Score
0.004
Published
2020-07-17
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a different vulnerability than CVE-2019-20011.
CVSS Score
8.1
EPSS Score
0.004
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.
CVSS Score
6.5
EPSS Score
0.003
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bit_read_TF.
CVSS Score
8.8
EPSS Score
0.004
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec.
CVSS Score
8.1
EPSS Score
0.004
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec.
CVSS Score
9.8
EPSS Score
0.004
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c.
CVSS Score
8.1
EPSS Score
0.004
Published
2020-07-16
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.
CVSS Score
7.5
EPSS Score
0.003
Published
2020-07-16
GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
CVSS Score
4.3
EPSS Score
0.011
Published
2020-06-24


Contact Us

Shodan ® - All rights reserved