VDB
GCVE-110-NCSC-2026-147
GCVE-110-NCSC-2026-147
Advisory PublishedCVSS 7.1/10
Multiple U-Boot versions, including DENX and Das U-Boot through 2019.07-rc4, contain vulnerabilities such as infinite recursion from crafted DOS partition tables causing crashes, alongside numerous CVEs from 2019-2020 affecting bootloader functionality and security.
Weaknesses (CWE)
CWE-121Stack-based Buffer OverflowCWE-407Inefficient Algorithmic ComplexityCWE-606Unchecked Input for Loop ConditionCWE-674Uncontrolled RecursionCWE-191Integer Underflow (Wrap or Wraparound)CWE-787Out-of-bounds WriteCWE-125Out-of-bounds ReadCWE-122Heap-based Buffer OverflowCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-416Use After FreeCWE-1286Improper Validation of Syntactic Correctness of InputCWE-754Improper Check for Unusual or Exceptional ConditionsCWE-277Insecure Inherited PermissionsCWE-476NULL Pointer DereferenceCWE-334Small Space of Random ValuesCWE-190Integer Overflow or WraparoundCWE-617Reachable AssertionCWE-131Incorrect Calculation of Buffer SizeCWE-328Use of Weak HashCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-770Allocation of Resources Without Limits or ThrottlingCWE-385Covert Timing ChannelCWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CWE-401Missing Release of Memory after Effective LifetimeCWE-667Improper LockingCWE-805Buffer Access with Incorrect Length ValueCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CWE-908Use of Uninitialized ResourceCWE-129Improper Validation of Array IndexCWE-415Double FreeCWE-772Missing Release of Resource after Effective LifetimeCWE-367Time-of-check Time-of-use (TOCTOU) Race ConditionCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-911Improper Update of Reference CountCWE-369Divide By ZeroCWE-1285Improper Validation of Specified Index, Position, or Offset in InputCWE-1025Comparison Using Wrong FactorsCWE-208Observable Timing DiscrepancyCWE-364Signal Handler Race ConditionCWE-573Improper Following of Specification by CallerCWE-273Improper Check for Dropped PrivilegesCWE-366Race Condition within a ThreadCWE-833DeadlockCWE-402Transmission of Private Resources into a New Sphere ('Resource Leak')CWE-321Use of Hard-coded Cryptographic KeyCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')CWE-404Improper Resource Shutdown or ReleaseCWE-825Expired Pointer DereferenceCWE-838Inappropriate Encoding for Output ContextCWE-23Relative Path TraversalCWE-150Improper Neutralization of Escape, Meta, or Control SequencesCWE-581Object Model Violation: Just One of Equals and Hashcode DefinedCWE-757Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')CWE-322Key Exchange without Entity AuthenticationCWE-1287Improper Validation of Specified Type of InputCWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')CWE-295Improper Certificate ValidationCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-306Missing Authentication for Critical FunctionCWE-1188Initialization of a Resource with an Insecure DefaultCWE-798Use of Hard-coded CredentialsCWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-824Access of Uninitialized Pointer
Risk Scores
CVSS 3.1
7.1/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Siemens AG | vers:unknown/* | — | — |
| Siemens | vers:unknown/* | — | — |
Aliases
CVE-2019-13103CVE-2019-13104CVE-2019-13106CVE-2019-14192CVE-2019-14193CVE-2019-14194CVE-2019-14195CVE-2019-14196CVE-2019-14197CVE-2019-14198CVE-2019-14199CVE-2019-14200CVE-2019-14201CVE-2019-14202CVE-2019-14203CVE-2019-14204CVE-2020-10648CVE-2022-2347CVE-2022-30552CVE-2022-30790CVE-2022-34835CVE-2023-27043CVE-2023-3019CVE-2024-22365CVE-2024-3447CVE-2024-4367CVE-2024-47704CVE-2024-54017CVE-2024-57256CVE-2024-57258CVE-2024-57924CVE-2024-58240CVE-2025-0395CVE-2025-12659CVE-2025-14831CVE-2025-22871CVE-2025-23143CVE-2025-23160CVE-2025-31257CVE-2025-3576CVE-2025-37931CVE-2025-37968CVE-2025-38322CVE-2025-38347CVE-2025-38491CVE-2025-38502CVE-2025-38552CVE-2025-38614CVE-2025-38670CVE-2025-38676CVE-2025-38677CVE-2025-38679CVE-2025-38680CVE-2025-38681CVE-2025-38683CVE-2025-38684CVE-2025-38685CVE-2025-38687CVE-2025-38691CVE-2025-38693CVE-2025-38694CVE-2025-38695CVE-2025-38696CVE-2025-38697CVE-2025-38698CVE-2025-38699CVE-2025-38700CVE-2025-38701CVE-2025-38702CVE-2025-38706CVE-2025-38707CVE-2025-38708CVE-2025-38711CVE-2025-38712CVE-2025-38713CVE-2025-38714CVE-2025-38715CVE-2025-38721CVE-2025-38723CVE-2025-38724CVE-2025-38725CVE-2025-38727CVE-2025-38728CVE-2025-38729CVE-2025-38732CVE-2025-38735CVE-2025-38736CVE-2025-39673CVE-2025-39675CVE-2025-39676CVE-2025-39681CVE-2025-39682CVE-2025-39683CVE-2025-39684CVE-2025-39685CVE-2025-39686CVE-2025-39687CVE-2025-39689CVE-2025-39691CVE-2025-39692CVE-2025-39693CVE-2025-39694CVE-2025-39697CVE-2025-39701CVE-2025-39702CVE-2025-39703CVE-2025-39706CVE-2025-39709CVE-2025-39710CVE-2025-39713CVE-2025-39714CVE-2025-39715CVE-2025-39716CVE-2025-39718CVE-2025-39719CVE-2025-39724CVE-2025-39736CVE-2025-39737CVE-2025-39738CVE-2025-39742CVE-2025-39743CVE-2025-39749CVE-2025-39752CVE-2025-39756CVE-2025-39757CVE-2025-39759CVE-2025-39760CVE-2025-39766CVE-2025-39770CVE-2025-39772CVE-2025-39773CVE-2025-39776CVE-2025-39782CVE-2025-39783CVE-2025-39787CVE-2025-39788CVE-2025-39790CVE-2025-39794CVE-2025-39795CVE-2025-39798CVE-2025-39800CVE-2025-39801CVE-2025-39806CVE-2025-39808CVE-2025-39812CVE-2025-39813CVE-2025-39817CVE-2025-39819CVE-2025-39823CVE-2025-39824CVE-2025-39825CVE-2025-39826CVE-2025-39827CVE-2025-39828CVE-2025-39835CVE-2025-39838CVE-2025-39839CVE-2025-39841CVE-2025-39842CVE-2025-39843CVE-2025-39844CVE-2025-39845CVE-2025-39846CVE-2025-39847CVE-2025-39848CVE-2025-39849CVE-2025-39853CVE-2025-39857CVE-2025-39860CVE-2025-39864CVE-2025-39865CVE-2025-39866CVE-2025-40300CVE-2025-40833CVE-2025-40946CVE-2025-40947CVE-2025-40948CVE-2025-40949CVE-2025-43368CVE-2025-46836CVE-2025-47219CVE-2025-48989CVE-2025-49794CVE-2025-49796CVE-2025-53057CVE-2025-53066CVE-2025-55752CVE-2025-55754CVE-2025-6020CVE-2025-6021CVE-2025-6052CVE-2025-61748CVE-2025-61795CVE-2025-7425CVE-2025-8916CVE-2025-9230CVE-2025-9231CVE-2025-9232CVE-2025-9714CVE-2025-9820CVE-2026-21925CVE-2026-21932CVE-2026-21933CVE-2026-21945CVE-2026-21947CVE-2026-22924CVE-2026-22925CVE-2026-25786CVE-2026-25787CVE-2026-25789CVE-2026-2673CVE-2026-27446CVE-2026-27662CVE-2026-28387CVE-2026-28388CVE-2026-28389CVE-2026-28390CVE-2026-31789CVE-2026-31790CVE-2026-33862CVE-2026-33893CVE-2026-40175CVE-2026-41125CVE-2026-41551CVE-2026-44411CVE-2026-44412
References
Browse GCVE Records
74,299 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.