Barebox

Vendor:

First CVE: Sep 5, 2019 · Active for 6 years

13
Total CVEs
More Total CVEs than 92% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Barebox over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 5, 2019
6 years ago
Most Recent CVE
May 16, 2026
73 days ago

CVE Severity & Scoring

Barebox13 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local5 (38.5%)
Network5 (38.5%)
Unknown0 (0.0%)
Physical2 (15.4%)
Adjacent Network1 (7.7%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (7.7%)
High1 (7.7%)
None11 (84.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
May 16, 20268.837NONO
barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation
May 11, 20268.435NONO
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length field is directly used for a memcpy.
Sep 5, 20199.832NONO
Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy.
Sep 5, 20199.832NONO
barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in f
May 11, 20267.730NONO
Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an incoming network packet is directly used as a length field wit
Jun 7, 20209.129NONO
barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to va
May 11, 20266.228NONO
barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature veri
Mar 20, 20268.228NONO
barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options poin
May 11, 20266.527NONO
common/password.c in Pengutronix barebox through 2021.07.0 leaks timing information because strncmp is used during hash comparison.
Aug 2, 20217.524NONO

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For Barebox

Top CWEs

Versions

No cataloged versions.