Логотип exploitDog
bind:"CVE-2020-14310"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-14310"

Количество 20

Количество 20

ubuntu логотип

CVE-2020-14310

почти 5 лет назад

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.

CVSS3: 5.7
EPSS: Низкий
redhat логотип

CVE-2020-14310

почти 5 лет назад

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2020-14310

почти 5 лет назад

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2020-14310

почти 5 лет назад

There is an issue on grub2 before version 2.06 at function read_sectio ...

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-849w-6cw8-9p7m

около 3 лет назад

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.

EPSS: Низкий
fstec логотип

BDU:2020-03969

почти 5 лет назад

Уязвимость реализации функции read_section_as_string() загрузчика операционных систем Grub2, позволяющая нарушителю оказать влияние на целостность данных или вызвать отказ в обслуживании

CVSS3: 5.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1169-1

почти 5 лет назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:1168-1

почти 5 лет назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2079-1

почти 5 лет назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2078-1

почти 5 лет назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2077-1

почти 5 лет назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2076-1

почти 5 лет назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2074-1

почти 5 лет назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2073-1

почти 5 лет назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:14440-1

почти 5 лет назад

Security update for grub2

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5790

почти 5 лет назад

ELSA-2020-5790: grub2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5786

почти 5 лет назад

ELSA-2020-5786: grub2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-5782

почти 5 лет назад

ELSA-2020-5782: grub2 security update (IMPORTANT)

EPSS: Низкий
msrc логотип

ADV200011

почти 4 года назад

Microsoft Guidance for Addressing Security Feature Bypass in GRUB

EPSS: Низкий
redos логотип

ROS-20220920-01

почти 3 года назад

Множественные уязвимости GRUB

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-14310

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.

CVSS3: 5.7
0%
Низкий
почти 5 лет назад
redhat логотип
CVE-2020-14310

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.

CVSS3: 5.7
0%
Низкий
почти 5 лет назад
nvd логотип
CVE-2020-14310

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.

CVSS3: 5.7
0%
Низкий
почти 5 лет назад
debian логотип
CVE-2020-14310

There is an issue on grub2 before version 2.06 at function read_sectio ...

CVSS3: 5.7
0%
Низкий
почти 5 лет назад
github логотип
GHSA-849w-6cw8-9p7m

There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file which has a name with UINT32_MAX, leading to read_section_as_string() to an arithmetic overflow, zero-sized allocation and further heap-based buffer overflow.

0%
Низкий
около 3 лет назад
fstec логотип
BDU:2020-03969

Уязвимость реализации функции read_section_as_string() загрузчика операционных систем Grub2, позволяющая нарушителю оказать влияние на целостность данных или вызвать отказ в обслуживании

CVSS3: 5.1
0%
Низкий
почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1169-1

Security update for grub2

почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:1168-1

Security update for grub2

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2079-1

Security update for grub2

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2078-1

Security update for grub2

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2077-1

Security update for grub2

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2076-1

Security update for grub2

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2074-1

Security update for grub2

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2073-1

Security update for grub2

почти 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:14440-1

Security update for grub2

почти 5 лет назад
oracle-oval логотип
ELSA-2020-5790

ELSA-2020-5790: grub2 security update (IMPORTANT)

почти 5 лет назад
oracle-oval логотип
ELSA-2020-5786

ELSA-2020-5786: grub2 security update (IMPORTANT)

почти 5 лет назад
oracle-oval логотип
ELSA-2020-5782

ELSA-2020-5782: grub2 security update (IMPORTANT)

почти 5 лет назад
msrc логотип
ADV200011

Microsoft Guidance for Addressing Security Feature Bypass in GRUB

почти 4 года назад
redos логотип
ROS-20220920-01

Множественные уязвимости GRUB

почти 3 года назад

Уязвимостей на страницу