Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-40551

Опубликовано: 29 янв. 2024
Источник: nvd
CVSS3: 5.1
EPSS Низкий

Описание

A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:shim:*:*:*:*:*:*:*:*
Версия до 15.8 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 2%
0.00017
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-125
CWE-125

Связанные уязвимости

CVSS3: 5.1
ubuntu
больше 1 года назад

A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.

CVSS3: 5.1
redhat
больше 1 года назад

A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.

CVSS3: 5.1
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 5.1
debian
больше 1 года назад

A flaw was found in the MZ binary format in Shim. An out-of-bounds rea ...

CVSS3: 5.1
github
больше 1 года назад

A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.

EPSS

Процентиль: 2%
0.00017
Низкий

5.1 Medium

CVSS3

Дефекты

CWE-125
CWE-125