VYPR

Shim

by Red Hat

CVEs (11)

  • CVE-2023-40547HigJan 25, 2024
    risk 0.54cvss 8.3epss 0.05

    A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlled out-of-bounds write…

  • CVE-2023-40548HigJan 29, 2024
    risk 0.48cvss 7.4epss 0.00

    A buffer overflow was found in Shim in the 32-bit system. The overflow happens due to an addition operation involving a user-controlled value parsed from the PE binary being used by Shim. This value is further used for memory allocation operations, leading to a heap-based buffer…

  • CVE-2022-28737MedJul 20, 2023
    risk 0.42cvss 6.5epss 0.00

    There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into…

  • CVE-2023-40549MedJan 29, 2024
    risk 0.40cvss 6.2epss 0.00

    An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.

  • CVE-2023-40546MedJan 29, 2024
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match the format string used by it,…

  • CVE-2023-40550MedJan 29, 2024
    risk 0.36cvss 5.5epss 0.00

    An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase.

  • CVE-2023-40551MedJan 29, 2024
    risk 0.33cvss 5.1epss 0.00

    A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.

  • CVE-2026-19411LowAug 10, 2026
    risk 0.25cvss 3.9epss 0.00

    A NULL pointer vulnerability has been found in the the shim application of dp.c library. A missing NULL pointer could allow attackers to perform a denial of service attack on a system that uses shim application for UEFI bootloader.

  • CVE-2014-3677Oct 22, 2014
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.

  • CVE-2014-3676Oct 22, 2014
    risk 0.00cvss epss 0.05

    Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."

  • CVE-2014-3675Oct 22, 2014
    risk 0.00cvss epss 0.03

    Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.