Home/Product/redhat shim
Product

redhat shim

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-40551
< 15.8
A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sens
5.1MEDIUM
CVE-2023-40550
< 15.8
An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data
5.5MEDIUM
CVE-2023-40549
< 15.8
An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This
6.2MEDIUM
CVE-2023-40546
< 15.8
A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tr
6.2MEDIUM
CVE-2023-40548
< 15.8
A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-contr
7.4HIGH
CVE-2023-40547
< 15.8
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an H
8.3HIGH
CVE-2022-28737
< 15.6
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() func
6.5MEDIUM
CVE-2014-8399
all versions
The default configuration in systemd-shim 8 enables the Abandon debugging clause, which allows local users to cause a denial of se
CVE-2014-3677
>= 0.3 and < 0.8
Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory co
CVE-2014-3676
>= 0.3 and < 0.8
Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "t
CVE-2014-3675
>= 0.3 and < 0.8
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin