Логотип exploitDog
bind:"GHSA-xxc4-h4cm-j5r2" OR bind:"CVE-2024-45780"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-xxc4-h4cm-j5r2" OR bind:"CVE-2024-45780"

Количество 11

Количество 11

github логотип

GHSA-xxc4-h4cm-j5r2

5 месяцев назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2024-45780

5 месяцев назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2024-45780

6 месяцев назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2024-45780

5 месяцев назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2024-45780

5 месяцев назад

A flaw was found in grub2. When reading tar files, grub2 allocates an ...

CVSS3: 6.7
EPSS: Низкий
fstec логотип

BDU:2025-03837

6 месяцев назад

Уязвимость компонента tar Handler загрузчика операционных систем Grub2, позволяющая нарушителю обойти механизм безопасной загрузки

CVSS3: 6.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0629-1

6 месяцев назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0607-1

6 месяцев назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0588-1

6 месяцев назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0587-1

6 месяцев назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0586-1

6 месяцев назад

Security update for grub2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxc4-h4cm-j5r2

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
0%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2024-45780

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2024-45780

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2024-45780

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
0%
Низкий
5 месяцев назад
debian логотип
CVE-2024-45780

A flaw was found in grub2. When reading tar files, grub2 allocates an ...

CVSS3: 6.7
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2025-03837

Уязвимость компонента tar Handler загрузчика операционных систем Grub2, позволяющая нарушителю обойти механизм безопасной загрузки

CVSS3: 6.7
0%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0629-1

Security update for grub2

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0607-1

Security update for grub2

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0588-1

Security update for grub2

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0587-1

Security update for grub2

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0586-1

Security update for grub2

6 месяцев назад

Уязвимостей на страницу