Known Vulnerabilities for Grub2 by Gnu
Listed below are 10 of the newest known vulnerabilities associated with "Grub2" by "Gnu".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-20233 | A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculati... | 8.2 - HIGH | 2021-03-03 | 2023-11-07 |
| CVE-2021-20225 | A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-all... | 6.7 - MEDIUM | 2021-03-03 | 2023-11-07 |
| CVE-2021-3981 | A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set all... | 3.3 - LOW | 2022-03-10 | 2024-01-16 |
| CVE-2021-3697 | A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in h... | 7 - HIGH | 2022-07-06 | 2023-09-13 |
| CVE-2021-3696 | A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corrupti... | 4.5 - MEDIUM | 2022-07-06 | 2023-09-13 |
| CVE-2021-3695 | A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of th... | 4.5 - MEDIUM | 2022-07-06 | 2023-09-13 |
| CVE-2021-3418 | If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without sig... | 6.4 - MEDIUM | 2021-03-15 | 2021-03-22 |
| CVE-2020-14309 | There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with na... | 6.7 - MEDIUM | 2020-07-30 | 2022-04-28 |
| CVE-2020-14308 | In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allo... | 6.4 - MEDIUM | 2020-07-29 | 2022-04-18 |
| CVE-2020-10713 | A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verificat... | 8.2 - HIGH | 2020-07-30 | 2022-11-16 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Grub2 | 2.06 | All | All | All |
| Application | Gnu | Grub2 | 2.04 | All | All | All |
| Application | Gnu | Grub2 | 2.02 | All | All | All |
| Application | Gnu | Grub2 | 2.01 | All | All | All |
| Application | Gnu | Grub2 | 2.00 | All | All | All |
| Application | Gnu | Grub2 | 1.99 | All | All | All |
| Application | Gnu | Grub2 | 1.98 | All | All | All |
| Application | Gnu | Grub2 | - | All | All | All |