Search CVE reports


Toggle filters

41 – 46 of 46 results


CVE-2018-3968

Medium priority
Not affected

An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to...

1 affected package

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Not affected Not affected
Show less packages

CVE-2018-18440

Negligible priority
Vulnerable

DENX U-Boot through 2018.09-rc1 has a locally exploitable buffer overflow via a crafted kernel image because filesystem loading is mishandled.

1 affected package

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-18439

Negligible priority
Vulnerable

DENX U-Boot through 2018.09-rc1 has a remotely exploitable buffer overflow via a malicious TFTP server because TFTP traffic is mishandled. Also, local exploitation can occur via a crafted kernel image.

1 affected package

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Not affected Not affected Not affected Not affected
Show less packages

CVE-2018-1000205

Negligible priority
Vulnerable

U-Boot contains a CWE-20: Improper Input Validation vulnerability in Verified boot signature validation that can result in Bypass verified boot. This attack appear to be exploitable via Specially crafted FIT image and special...

1 affected package

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-3226

Negligible priority
Vulnerable

Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of Das U-Boot's AES-CBC encryption feature using environment encryption (i.e., setting the configuration parameter...

1 affected package

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Not affected Not affected Not affected Not affected
Show less packages

CVE-2017-3225

Negligible priority
Ignored

Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. For devices utilizing this environment encryption mode, U-Boot's use of a zero initialization vector may allow attacks against...

1 affected package

u-boot

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
u-boot Not affected Not affected
Show less packages