VDB

CVE-2015-8370

CVE-2015-8370 PUBLISHED CVSS 7.400000095367432 HIGH

Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.

EPSS 1.10% · 64.3th percentile

Risk Scores

CVSS 3.1
7.400000095367432
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.10%
64.3th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSgrub20, 2.00-19ubuntu2, 2.00-19ubuntu3

Timeline

  • Dec 11, 2015 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 15, 2022 EPSS Score
  • Sep 6, 2022 EPSS Score
  • Oct 29, 2022 EPSS Score
  • Dec 21, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 6, 2023 EPSS Score
  • May 30, 2023 EPSS Score
  • Jul 22, 2023 EPSS Score
  • Nov 5, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›