Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

github логотип

GHSA-q7w8-q2f9-vcmh

больше 1 года назад

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2025-0689

больше 1 года назад

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2025-0689

больше 1 года назад

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2025-0689

больше 1 года назад

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2025-0689

11 месяцев назад

Grub2: udf: heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution

CVSS3: 6.4
EPSS: Низкий
debian логотип

CVE-2025-0689

больше 1 года назад

When reading data from disk, the grub's UDF filesystem module utilizes ...

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2025-07125

больше 1 года назад

Уязвимость функции grub_udf_read_block загрузчика операционных систем Grub2, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0629-1

больше 1 года назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0607-1

больше 1 года назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0588-1

больше 1 года назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0587-1

больше 1 года назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0586-1

больше 1 года назад

Security update for grub2

EPSS: Низкий
redos логотип

ROS-20250818-06

12 месяцев назад

Множественные уязвимости grub2-common

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-q7w8-q2f9-vcmh

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 6.4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-0689

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2025-0689

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-0689

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is always smaller than the allocated buffer size which is not guaranteed. A crafted filesystem image may lead to a heap-based buffer overflow resulting in critical data to be corrupted, resulting in the risk of arbitrary code execution by-passing secure boot protections.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2025-0689

Grub2: udf: heap based buffer overflow in grub_udf_read_block() may lead to arbitrary code execution

CVSS3: 6.4
0%
Низкий
11 месяцев назад
debian логотип
CVE-2025-0689

When reading data from disk, the grub's UDF filesystem module utilizes ...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-07125

Уязвимость функции grub_udf_read_block загрузчика операционных систем Grub2, позволяющая нарушителю оказать влияние на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0629-1

Security update for grub2

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0607-1

Security update for grub2

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0588-1

Security update for grub2

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0587-1

Security update for grub2

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0586-1

Security update for grub2

больше 1 года назад
redos логотип
ROS-20250818-06

Множественные уязвимости grub2-common

CVSS3: 8.8
12 месяцев назад

Уязвимостей на страницу