Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

11 – 20 of 38 results


CVE-2021-27097

Low priority
Ignored

The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.

1 affected packages

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
u-boot Not affected Ignored Ignored Ignored
Show less packages

CVE-2020-10648

Low priority

Some fixes available 2 of 4

Das U-Boot through 2020.01 allows attackers to bypass verified boot restrictions and subsequently boot arbitrary images by providing a crafted FIT image to a system configured to boot the default configuration.

1 affected packages

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
u-boot Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2020-8432

Low priority

Some fixes available 2 of 3

In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this...

1 affected packages

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
u-boot Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-13106

Low priority

Some fixes available 2 of 4

Das U-Boot versions 2016.09 through 2019.07-rc4 can memset() too much data while reading a crafted ext4 filesystem, which results in a stack buffer overflow and likely code execution.

1 affected packages

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
u-boot Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-13105

Low priority
Not affected

Das U-Boot versions 2019.07-rc1 through 2019.07-rc4 can double-free a cached block of data when listing files in a crafted ext4 filesystem.

1 affected packages

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
u-boot Not affected Not affected
Show less packages

CVE-2019-13104

Low priority

Some fixes available 2 of 4

In Das U-Boot versions 2016.11-rc1 through 2019.07-rc4, an underflow can cause memcpy() to overwrite a very large amount of data (including the whole stack) while reading a crafted ext4 filesystem.

1 affected packages

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
u-boot Not affected Fixed Fixed Not affected
Show less packages

CVE-2019-14204

Low priority

Some fixes available 2 of 5

An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_umountall_reply.

1 affected packages

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
u-boot Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2019-14203

Low priority

Some fixes available 2 of 5

An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_mount_reply.

1 affected packages

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
u-boot Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2019-14202

Low priority

Some fixes available 2 of 5

An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_readlink_reply.

1 affected packages

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
u-boot Not affected Not affected Fixed Fixed Vulnerable
Show less packages

CVE-2019-14201

Low priority

Some fixes available 2 of 5

An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_lookup_reply.

1 affected packages

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
u-boot Not affected Not affected Fixed Fixed Vulnerable
Show less packages