VendorsTianoCoreedk2any version
Vulnerabilities

TianoCore EDK II any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2021-38578
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Published 2022-03-03 · Modified
9.8EPSS 0.010
CVE-2023-45230
Buffer Overflow in EDK II Network Package
Published 2024-01-16 · Modified
8.8EPSS 0.012
CVE-2023-45235
Buffer Overflow in EDK II Network Package
Published 2024-01-16 · Modified
8.8EPSS 0.012
CVE-2023-45234
Buffer Overflow in EDK II Network Package
Published 2024-01-16 · Modified
8.8EPSS 0.012
CVE-2021-38575
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
Published 2021-12-01 · Modified
8.1EPSS 0.019
CVE-2019-14586
Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.
Published 2020-11-23 · Modified
8.0EPSS 0.007
CVE-2019-14563
Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2020-11-23 · Modified
7.8EPSS 0.004
CVE-2021-28210
An unlimited recursion in DxeCore in EDK II.
Published 2021-06-11 · Modified
7.8EPSS 0.004
CVE-2017-5731
Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escalation of privilege via local access.
Published 2019-10-28 · Modified
7.8EPSS 0.004
CVE-2019-14575
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2020-11-23 · Modified
7.8EPSS 0.004
CVE-2019-14584
Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2021-06-03 · Modified
7.8EPSS 0.003
CVE-2022-36763
Heap Buffer Overflow in Tcg2MeasureGptTable
Published 2024-01-09 · Modified
7.8EPSS 0.003
CVE-2022-36765
Integer Overflow in CreateHob
Published 2024-01-09 · Modified
7.8EPSS 0.003
CVE-2022-36764
Heap Buffer Overflow in Tcg2MeasurePeImage
Published 2024-01-09 · Modified
7.8EPSS 0.003
CVE-2023-45232
Infinite loop in EDK II Network Package
Published 2024-01-16 · Modified
7.5EPSS 0.021
CVE-2023-45233
Infinite loop in EDK II Network Package
Published 2024-01-16 · Modified
7.5EPSS 0.021
CVE-2019-14559
Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.
Published 2020-11-23 · Modified
7.5EPSS 0.013
CVE-2023-45236
Predictable TCP ISNs in EDK II Network Package
Published 2024-01-16 · Modified
7.5EPSS 0.010
CVE-2023-45237
Use of a Weak PseudoRandom Number Generator in EDK II Network Package
Published 2024-01-16 · Modified
7.5EPSS 0.010
CVE-2014-4859
Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.
Published 2020-01-31 · Modified
7.2EPSS 0.006
CVE-2014-4860
Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase.
Published 2020-01-31 · Modified
7.2EPSS 0.005
CVE-2014-8271
Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variable name.
Published 2020-02-06 · Modified
6.8EPSS 0.004
CVE-2023-48733
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Published 2024-02-14 · Analyzed
6.7EPSS 0.003
CVE-2023-49721
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
Published 2024-02-14 · Analyzed
6.7EPSS 0.002
CVE-2023-45229
Out-of-Bounds Read in EDK II Network Package
Published 2024-01-16 · Modified
6.5EPSS 0.009
CVE-2023-45231
Out-of-Bounds Read in EDK II Network Package
Published 2024-01-16 · Modified
6.5EPSS 0.009
CVE-2019-14587
Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Published 2020-11-23 · Modified
6.5EPSS 0.006
CVE-2019-14562
Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
Published 2020-11-23 · Modified
5.5EPSS 0.003
CVE-2019-14553
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
Published 2020-11-23 · Modified
4.9EPSS 0.014