Логотип exploitDog
bind:"GHSA-xxc4-h4cm-j5r2" OR bind:"CVE-2024-45780"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-xxc4-h4cm-j5r2" OR bind:"CVE-2024-45780"

Количество 13

Количество 13

github логотип

GHSA-xxc4-h4cm-j5r2

около 1 года назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
EPSS: Низкий
ubuntu логотип

CVE-2024-45780

около 1 года назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
EPSS: Низкий
redhat логотип

CVE-2024-45780

около 1 года назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2024-45780

около 1 года назад

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
EPSS: Низкий
msrc логотип

CVE-2024-45780

7 месяцев назад

Grub2: fs/tar: integer overflow causes heap oob write

CVSS3: 6.7
EPSS: Низкий
debian логотип

CVE-2024-45780

около 1 года назад

A flaw was found in grub2. When reading tar files, grub2 allocates an ...

CVSS3: 6.7
EPSS: Низкий
fstec логотип

BDU:2025-03837

около 1 года назад

Уязвимость компонента tar Handler загрузчика операционных систем Grub2, позволяющая нарушителю обойти механизм безопасной загрузки

CVSS3: 6.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0629-1

около 1 года назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0607-1

около 1 года назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0588-1

около 1 года назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0587-1

около 1 года назад

Security update for grub2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0586-1

около 1 года назад

Security update for grub2

EPSS: Низкий
redos логотип

ROS-20250818-06

7 месяцев назад

Множественные уязвимости grub2-common

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xxc4-h4cm-j5r2

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-45780

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-45780

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-45780

A flaw was found in grub2. When reading tar files, grub2 allocates an internal buffer for the file name. However, it fails to properly verify the allocation against possible integer overflows. It's possible to cause the allocation length to overflow with a crafted tar file, leading to a heap out-of-bounds write. This flaw eventually allows an attacker to circumvent secure boot protections.

CVSS3: 6.7
0%
Низкий
около 1 года назад
msrc логотип
CVE-2024-45780

Grub2: fs/tar: integer overflow causes heap oob write

CVSS3: 6.7
0%
Низкий
7 месяцев назад
debian логотип
CVE-2024-45780

A flaw was found in grub2. When reading tar files, grub2 allocates an ...

CVSS3: 6.7
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-03837

Уязвимость компонента tar Handler загрузчика операционных систем Grub2, позволяющая нарушителю обойти механизм безопасной загрузки

CVSS3: 6.7
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0629-1

Security update for grub2

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0607-1

Security update for grub2

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0588-1

Security update for grub2

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0587-1

Security update for grub2

около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0586-1

Security update for grub2

около 1 года назад
redos логотип
ROS-20250818-06

Множественные уязвимости grub2-common

CVSS3: 8.8
7 месяцев назад

Уязвимостей на страницу