VDB

GCVE-110-NCSC-2026-147

GCVE-110-NCSC-2026-147
Advisory PublishedCVSS 7.1/10
Vulnetix · Advisory published May 13, 2026
Multiple U-Boot versions, including DENX and Das U-Boot through 2019.07-rc4, contain vulnerabilities such as infinite recursion from crafted DOS partition tables causing crashes, alongside numerous CVEs from 2019-2020 affecting bootloader functionality and security.

Weaknesses (CWE)

CWE-121Stack-based Buffer OverflowCWE-407Inefficient Algorithmic ComplexityCWE-606Unchecked Input for Loop ConditionCWE-674Uncontrolled RecursionCWE-191Integer Underflow (Wrap or Wraparound)CWE-787Out-of-bounds WriteCWE-125Out-of-bounds ReadCWE-122Heap-based Buffer OverflowCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-416Use After FreeCWE-1286Improper Validation of Syntactic Correctness of InputCWE-754Improper Check for Unusual or Exceptional ConditionsCWE-277Insecure Inherited PermissionsCWE-476NULL Pointer DereferenceCWE-334Small Space of Random ValuesCWE-190Integer Overflow or WraparoundCWE-617Reachable AssertionCWE-131Incorrect Calculation of Buffer SizeCWE-328Use of Weak HashCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-770Allocation of Resources Without Limits or ThrottlingCWE-385Covert Timing ChannelCWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CWE-401Missing Release of Memory after Effective LifetimeCWE-667Improper LockingCWE-805Buffer Access with Incorrect Length ValueCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CWE-908Use of Uninitialized ResourceCWE-129Improper Validation of Array IndexCWE-415Double FreeCWE-772Missing Release of Resource after Effective LifetimeCWE-367Time-of-check Time-of-use (TOCTOU) Race ConditionCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-911Improper Update of Reference CountCWE-369Divide By ZeroCWE-1285Improper Validation of Specified Index, Position, or Offset in InputCWE-1025Comparison Using Wrong FactorsCWE-208Observable Timing DiscrepancyCWE-364Signal Handler Race ConditionCWE-573Improper Following of Specification by CallerCWE-273Improper Check for Dropped PrivilegesCWE-366Race Condition within a ThreadCWE-833DeadlockCWE-402Transmission of Private Resources into a New Sphere ('Resource Leak')CWE-321Use of Hard-coded Cryptographic KeyCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')CWE-404Improper Resource Shutdown or ReleaseCWE-825Expired Pointer DereferenceCWE-838Inappropriate Encoding for Output ContextCWE-23Relative Path TraversalCWE-150Improper Neutralization of Escape, Meta, or Control SequencesCWE-581Object Model Violation: Just One of Equals and Hashcode DefinedCWE-757Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')CWE-322Key Exchange without Entity AuthenticationCWE-1287Improper Validation of Specified Type of InputCWE-93Improper Neutralization of CRLF Sequences ('CRLF Injection')CWE-295Improper Certificate ValidationCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-306Missing Authentication for Critical FunctionCWE-1188Initialization of a Resource with an Insecure DefaultCWE-798Use of Hard-coded CredentialsCWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')CWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-824Access of Uninitialized Pointer

Risk Scores

CVSS 3.1
7.1/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
Siemens AGvers:unknown/*
Siemensvers:unknown/*

Aliases

CVE-2019-13103CVE-2019-13104CVE-2019-13106CVE-2019-14192CVE-2019-14193CVE-2019-14194CVE-2019-14195CVE-2019-14196CVE-2019-14197CVE-2019-14198CVE-2019-14199CVE-2019-14200CVE-2019-14201CVE-2019-14202CVE-2019-14203CVE-2019-14204CVE-2020-10648CVE-2022-2347CVE-2022-30552CVE-2022-30790CVE-2022-34835CVE-2023-27043CVE-2023-3019CVE-2024-22365CVE-2024-3447CVE-2024-4367CVE-2024-47704CVE-2024-54017CVE-2024-57256CVE-2024-57258CVE-2024-57924CVE-2024-58240CVE-2025-0395CVE-2025-12659CVE-2025-14831CVE-2025-22871CVE-2025-23143CVE-2025-23160CVE-2025-31257CVE-2025-3576CVE-2025-37931CVE-2025-37968CVE-2025-38322CVE-2025-38347CVE-2025-38491CVE-2025-38502CVE-2025-38552CVE-2025-38614CVE-2025-38670CVE-2025-38676CVE-2025-38677CVE-2025-38679CVE-2025-38680CVE-2025-38681CVE-2025-38683CVE-2025-38684CVE-2025-38685CVE-2025-38687CVE-2025-38691CVE-2025-38693CVE-2025-38694CVE-2025-38695CVE-2025-38696CVE-2025-38697CVE-2025-38698CVE-2025-38699CVE-2025-38700CVE-2025-38701CVE-2025-38702CVE-2025-38706CVE-2025-38707CVE-2025-38708CVE-2025-38711CVE-2025-38712CVE-2025-38713CVE-2025-38714CVE-2025-38715CVE-2025-38721CVE-2025-38723CVE-2025-38724CVE-2025-38725CVE-2025-38727CVE-2025-38728CVE-2025-38729CVE-2025-38732CVE-2025-38735CVE-2025-38736CVE-2025-39673CVE-2025-39675CVE-2025-39676CVE-2025-39681CVE-2025-39682CVE-2025-39683CVE-2025-39684CVE-2025-39685CVE-2025-39686CVE-2025-39687CVE-2025-39689CVE-2025-39691CVE-2025-39692CVE-2025-39693CVE-2025-39694CVE-2025-39697CVE-2025-39701CVE-2025-39702CVE-2025-39703CVE-2025-39706CVE-2025-39709CVE-2025-39710CVE-2025-39713CVE-2025-39714CVE-2025-39715CVE-2025-39716CVE-2025-39718CVE-2025-39719CVE-2025-39724CVE-2025-39736CVE-2025-39737CVE-2025-39738CVE-2025-39742CVE-2025-39743CVE-2025-39749CVE-2025-39752CVE-2025-39756CVE-2025-39757CVE-2025-39759CVE-2025-39760CVE-2025-39766CVE-2025-39770CVE-2025-39772CVE-2025-39773CVE-2025-39776CVE-2025-39782CVE-2025-39783CVE-2025-39787CVE-2025-39788CVE-2025-39790CVE-2025-39794CVE-2025-39795CVE-2025-39798CVE-2025-39800CVE-2025-39801CVE-2025-39806CVE-2025-39808CVE-2025-39812CVE-2025-39813CVE-2025-39817CVE-2025-39819CVE-2025-39823CVE-2025-39824CVE-2025-39825CVE-2025-39826CVE-2025-39827CVE-2025-39828CVE-2025-39835CVE-2025-39838CVE-2025-39839CVE-2025-39841CVE-2025-39842CVE-2025-39843CVE-2025-39844CVE-2025-39845CVE-2025-39846CVE-2025-39847CVE-2025-39848CVE-2025-39849CVE-2025-39853CVE-2025-39857CVE-2025-39860CVE-2025-39864CVE-2025-39865CVE-2025-39866CVE-2025-40300CVE-2025-40833CVE-2025-40946CVE-2025-40947CVE-2025-40948CVE-2025-40949CVE-2025-43368CVE-2025-46836CVE-2025-47219CVE-2025-48989CVE-2025-49794CVE-2025-49796CVE-2025-53057CVE-2025-53066CVE-2025-55752CVE-2025-55754CVE-2025-6020CVE-2025-6021CVE-2025-6052CVE-2025-61748CVE-2025-61795CVE-2025-7425CVE-2025-8916CVE-2025-9230CVE-2025-9231CVE-2025-9232CVE-2025-9714CVE-2025-9820CVE-2026-21925CVE-2026-21932CVE-2026-21933CVE-2026-21945CVE-2026-21947CVE-2026-22924CVE-2026-22925CVE-2026-25786CVE-2026-25787CVE-2026-25789CVE-2026-2673CVE-2026-27446CVE-2026-27662CVE-2026-28387CVE-2026-28388CVE-2026-28389CVE-2026-28390CVE-2026-31789CVE-2026-31790CVE-2026-33862CVE-2026-33893CVE-2026-40175CVE-2026-41125CVE-2026-41551CVE-2026-44411CVE-2026-44412

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,299 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›