Show filters
1,191 Total Results
Displaying 291-300 of 1,191
Sort by:
Attacker Value
Unknown
CVE-2020-15707
Disclosure Date: July 29, 2020 (last updated February 21, 2025)
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.
0
Attacker Value
Unknown
CVE-2020-15705
Disclosure Date: July 29, 2020 (last updated February 21, 2025)
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.
0
Attacker Value
Unknown
CVE-2020-15807
Disclosure Date: July 17, 2020 (last updated February 21, 2025)
GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files.
0
Attacker Value
Unknown
CVE-2019-20909
Disclosure Date: July 16, 2020 (last updated February 21, 2025)
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec.
0
Attacker Value
Unknown
CVE-2019-20911
Disclosure Date: July 16, 2020 (last updated February 21, 2025)
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop.
0
Attacker Value
Unknown
CVE-2019-20915
Disclosure Date: July 16, 2020 (last updated February 21, 2025)
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c.
0
Attacker Value
Unknown
CVE-2019-20910
Disclosure Date: July 16, 2020 (last updated February 21, 2025)
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a different vulnerability than CVE-2019-20011.
0
Attacker Value
Unknown
CVE-2019-20914
Disclosure Date: July 16, 2020 (last updated February 21, 2025)
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec.
0
Attacker Value
Unknown
CVE-2019-20912
Disclosure Date: July 16, 2020 (last updated February 21, 2025)
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bit_read_TF.
0
Attacker Value
Unknown
CVE-2019-20913
Disclosure Date: July 16, 2020 (last updated February 21, 2025)
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec.
0