Shim
This hub aggregates every CVE we track for Shim, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Operating Systemson-prem
11
CVEs tracked
0
Critical
4
High
0
In CISA KEV
Severity distribution
MEDIUM6HIGH4LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 11 most recently published vulnerabilities affecting Shim.
- CVE-2023-40551Shim: out of bounds read when parsing mz binaries5.1
- CVE-2023-40549Shim: out-of-bounds read in verify_buffer_authenticode() malformed pe file6.2
- CVE-2023-40546Shim: out-of-bounds read printing error messages6.2
- CVE-2023-40550Shim: out-of-bound read in verify_buffer_sbat()5.5
- CVE-2023-40548Shim: interger overflow leads to heap buffer overflow in verify_sbat_section on 32-bits systems7.4
- CVE-2023-40547Shim: rce in http boot support may lead to secure boot bypass8.3
- CVE-2022-28737There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables6.5
- CVE-2014-8399The default configuration in systemd-shim 8 enables the Abandon debugging clause, which allows local users to cause a denial of service via unspecified vectors.2.1
- CVE-2014-3676Heap-based buffer overflow in Shim allows remote attackers to execute arbitrary code via a crafted IPv6 address, related to the "tftp:// DHCPv6 boot option."7.5
- CVE-2014-3677Unspecified vulnerability in Shim might allow attackers to execute arbitrary code via a crafted MOK list, which triggers memory corruption.7.5
- CVE-2014-3675Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.5.0
Product normalization is registry-driven with AI assist and human review. How it works