CVE-2025-0685
- EPSS 0.02%
- Published 03.03.2025 18:15:30
- Last modified 28.07.2025 17:23:03
A flaw was found in grub2. When reading data from a jfs filesystem, grub's jfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for integer overflows. ...
CVE-2025-0686
- EPSS 0.02%
- Published 03.03.2025 18:15:30
- Last modified 28.07.2025 17:23:26
A flaw was found in grub2. When performing a symlink lookup from a romfs filesystem, grub's romfs filesystem module uses user-controlled parameters from the filesystem geometry to determine the internal buffer size, however, it improperly checks for ...
CVE-2025-0689
- EPSS 0.02%
- Published 03.03.2025 15:15:16
- Last modified 12.08.2025 14:15:27
When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is al...
CVE-2025-1125
- EPSS 0.02%
- Published 03.03.2025 15:15:16
- Last modified 12.08.2025 14:15:27
When reading data from a hfs filesystem, grub's hfs filesystem module uses user-controlled parameters from the filesystem metadata to calculate the internal buffers size, however it misses to properly check for integer overflows. A maliciouly crafted...
CVE-2023-4949
- EPSS 0.03%
- Published 10.11.2023 17:15:07
- Last modified 21.11.2024 08:36:19
An attacker with local access to a system (either through a disk or external drive) can present a modified XFS partition to grub-legacy in such a way to exploit a memory corruption in grub’s XFS file system implementation.
CVE-2013-4577
- EPSS 0.16%
- Published 12.05.2014 14:55:05
- Last modified 12.04.2025 10:46:40
A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.