Barebox
Vendor:
First CVE: Sep 5, 2019 · Active for 6 years
13
Total CVEs
More Total CVEs than 92% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Barebox over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 5, 2019
6 years ago
Most Recent CVE
May 16, 2026
73 days ago
CVE Severity & Scoring
Barebox13 CVEs
15%
62%
23%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local5 (38.5%)
Network5 (38.5%)
Unknown0 (0.0%)
Physical2 (15.4%)
Adjacent Network1 (7.7%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (7.7%)
High1 (7.7%)
None11 (84.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-46728HIGH Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash. | May 16, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-34963HIGH barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation | May 11, 2026 | 8.4 | 35 | NO | NO |
CVE-2019-15938CRITICAL Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_req in fs/nfs.c because a length field is directly used for a memcpy. | Sep 5, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-15937CRITICAL Pengutronix barebox through 2019.08.1 has a remote buffer overflow in nfs_readlink_reply in net/nfs.c because a length field is directly used for a memcpy. | Sep 5, 2019 | 9.8 | 32 | NO | NO |
CVE-2026-34961HIGH barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in f | May 11, 2026 | 7.7 | 30 | NO | NO |
CVE-2020-13910CRITICAL Pengutronix Barebox through v2020.05.0 has an out-of-bounds read in nfs_read_reply in net/nfs.c because a field of an incoming network packet is directly used as a length field wit | Jun 7, 2020 | 9.1 | 29 | NO | NO |
CVE-2026-34962MEDIUM barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to va | May 11, 2026 | 6.2 | 28 | NO | NO |
CVE-2026-33243HIGH barebox is a bootloader. In barebox from version 2016.03.0 to before version 2026.03.1 (and the corresponding backport to 2025.09.3), an attacker could exploit a FIT signature veri | Mar 20, 2026 | 8.2 | 28 | NO | NO |
CVE-2026-34960MEDIUM barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options poin | May 11, 2026 | 6.5 | 27 | NO | NO |
CVE-2021-37848HIGH common/password.c in Pengutronix barebox through 2021.07.0 leaks timing information because strncmp is used during hash comparison. | Aug 2, 2021 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Barebox
Top CWEs
Versions
No cataloged versions.