Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2022-28737
Description:There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2022.2280   1.3.6.1.4.1.25623.1.1.2.2022.2591   1.3.6.1.4.1.25623.1.1.4.2023.1863.1   1.3.6.1.4.1.25623.1.1.2.2022.2538   1.3.6.1.4.1.25623.1.1.2.2022.2367   1.3.6.1.4.1.25623.1.1.2.2022.2235   1.3.6.1.4.1.25623.1.1.2.2022.2635   1.3.6.1.4.1.25623.1.1.2.2022.2333   1.3.6.1.4.1.25623.1.0.820763   1.3.6.1.4.1.25623.1.0.820761   1.3.6.1.4.1.25623.1.1.2.2022.2403   1.3.6.1.4.1.25623.1.1.4.2023.1702.1   1.3.6.1.4.1.25623.1.1.2.2022.2919   1.3.6.1.4.1.25623.1.1.2.2022.2667   1.3.6.1.4.1.25623.1.1.4.2023.2084.1   1.3.6.1.4.1.25623.1.1.4.2023.2150.1   1.3.6.1.4.1.25623.1.1.4.2023.2091.1   1.3.6.1.4.1.25623.1.1.2.2022.2304   1.3.6.1.4.1.25623.1.1.2.2022.2699   1.3.6.1.4.1.25623.1.1.4.2023.2086.1   1.3.6.1.4.1.25623.1.1.2.2022.2945   1.3.6.1.4.1.25623.1.0.820766  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2022-28737
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28737
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28737
https://www.openwall.com/lists/oss-security/2022/06/07/5
https://www.openwall.com/lists/oss-security/2022/06/07/5




© 1998-2025 E-Soft Inc. All rights reserved.