cbcvebase.

Gnu Grub2 vulnerabilities

64 known vulnerabilities affecting gnu/grub2.

Total CVEs
64
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH24MEDIUM38LOW2

Vulnerabilities

Page 4 of 4
CVE-2025-1118P4MEDIUMCVSS 4.4≥ 0, < 2.12-62025-02-19
CVE-2025-1118 [MEDIUM] CVE-2025-1118: A flaw was found in grub2 A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other sensitive information from the memory.
osv
CVE-2024-45783P4MEDIUMCVSS 4.4≥ 0, < 2.12-62025-02-18
CVE-2024-45783 [MEDIUM] CVE-2024-45783: A flaw was found in grub2 A flaw was found in grub2. When failing to mount an HFS+ grub, the hfsplus filesystem driver doesn't properly set an ERRNO value. This issue may lead to a NULL pointer access.
osv
CVE-2021-3981P4LOWCVSS 3.3≤ 2.06vgrub2 2.06 and previous versions2022-03-10
CVE-2021-3981 [LOW] CWE-276 CVE-2021-3981: A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content. This represents a low severity confidentiality issue, as those users can eventually read any encrypted passwords present in grub.cfg. This flaw affects grub2 2.06 and previous version
nvdosv
CVE-2013-4577P4LOWCVSS 2.1≥ 0, < 2.00-202014-05-12
CVE-2013-4577 [LOW] CVE-2013-4577: A certain Debian patch for GNU GRUB uses world-readable permissions for grub A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.
osv
Gnu Grub2 vulnerabilities | cvebase