Vulnerabilities (CVE)

Filtered by vendor Tianocore Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-38575 2 Insyde, Tianocore 2 Kernel, Edk2 2023-08-02 6.8 MEDIUM 8.1 HIGH
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
CVE-2021-28213 1 Tianocore 1 Edk2 2022-07-12 5.0 MEDIUM 7.5 HIGH
Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.
CVE-2021-38576 1 Tianocore 1 Edk2 2022-01-13 7.8 HIGH 7.5 HIGH
A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.
CVE-2019-14575 2 Debian, Tianocore 2 Debian Linux, Edk2 2022-01-01 4.6 MEDIUM 7.8 HIGH
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2019-14586 2 Debian, Tianocore 2 Debian Linux, Edk2 2022-01-01 5.2 MEDIUM 8.0 HIGH
Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.
CVE-2019-14563 2 Debian, Tianocore 2 Debian Linux, Edk2 2022-01-01 4.6 MEDIUM 7.8 HIGH
Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2019-14559 1 Tianocore 1 Edk2 2022-01-01 5.0 MEDIUM 7.5 HIGH
Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.
CVE-2021-28216 1 Tianocore 1 Edk Ii 2021-08-16 4.6 MEDIUM 7.8 HIGH
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
CVE-2021-28210 1 Tianocore 1 Edk2 2021-06-24 4.6 MEDIUM 7.8 HIGH
An unlimited recursion in DxeCore in EDK II.
CVE-2019-14584 1 Tianocore 1 Edk2 2021-06-11 4.6 MEDIUM 7.8 HIGH
Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2018-12179 1 Tianocore 1 Edk Ii 2020-08-24 4.6 MEDIUM 7.8 HIGH
Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
CVE-2017-5731 1 Tianocore 1 Edk2 2019-11-18 4.6 MEDIUM 7.8 HIGH
Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escalation of privilege via local access.
CVE-2018-12180 2 Opensuse, Tianocore 2 Leap, Edk Ii 2019-10-03 6.8 MEDIUM 8.8 HIGH
Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.
CVE-2018-3613 1 Tianocore 1 Edk Ii 2019-10-03 4.6 MEDIUM 7.8 HIGH
Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.