VendorsTianoCoreedk_iiall versions
Vulnerabilities

TianoCore EDK II

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2019-0160
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
Published 2019-03-27 · Modified
9.8EPSS 0.013
CVE-2018-12178
Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.
Published 2019-03-27 · Modified
9.1EPSS 0.023
CVE-2018-12180
Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.
Published 2019-03-27 · Modified
8.8EPSS 0.023
CVE-2018-3613
Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Published 2019-03-27 · Modified
7.8EPSS 0.004
CVE-2021-28216
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
Published 2021-08-05 · Modified
7.8EPSS 0.004
CVE-2018-12179
Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Published 2019-03-27 · Modified
7.8EPSS 0.004
CVE-2018-12183
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Published 2019-03-27 · Modified
6.8EPSS 0.005
CVE-2019-11098
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
Published 2021-07-14 · Modified
6.8EPSS 0.003
CVE-2018-12182
Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
Published 2019-03-27 · Modified
6.7EPSS 0.004
CVE-2018-12181
Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.
Published 2019-03-27 · Modified
6.0EPSS 0.004
CVE-2019-0161
Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access.
Published 2019-03-27 · Modified
5.5EPSS 0.004