Shim Project maintains a specialized bootloader component that bridges firmware and operating-system initialization on UEFI systems, a critical but narrow scope in the platform boot stack. The sparse vulnerability record centers on the shim product itself and reflects the challenge of characterizing security issues in low-level firmware code where root-cause analysis often yields incomplete information. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shim Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
The default configuration in systemd-shim 8 enables the Abandon debugging clause, which allows local users to cause a denial of service via unspecified vectors. | Oct 31, 2014 | 2.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shim Project.
Media articles that mention a CVE ID that affects a product developed by Shim Project — matched by CVE ID, not by vendor name.