Show filters
32 Total Results
Displaying 11-20 of 32
Sort by:
Attacker Value
Unknown
CVE-2023-45229
Disclosure Date: January 16, 2024 (last updated January 24, 2024)
EDK2's Network Package is susceptible to an out-of-bounds read
vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message. This
vulnerability can be exploited by an attacker to gain unauthorized
access and potentially lead to a loss of Confidentiality.
0
Attacker Value
Unknown
CVE-2022-36765
Disclosure Date: January 09, 2024 (last updated February 14, 2025)
EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
0
Attacker Value
Unknown
CVE-2022-36764
Disclosure Date: January 09, 2024 (last updated February 14, 2025)
EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
0
Attacker Value
Unknown
CVE-2022-36763
Disclosure Date: January 09, 2024 (last updated February 14, 2025)
EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability.
0
Attacker Value
Unknown
CVE-2021-38578
Disclosure Date: March 03, 2022 (last updated February 23, 2025)
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
0
Attacker Value
Unknown
CVE-2021-38576
Disclosure Date: January 03, 2022 (last updated October 07, 2023)
A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.
0
Attacker Value
Unknown
CVE-2021-38575
Disclosure Date: December 01, 2021 (last updated February 23, 2025)
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
0
Attacker Value
Unknown
CVE-2021-28210
Disclosure Date: June 11, 2021 (last updated February 22, 2025)
An unlimited recursion in DxeCore in EDK II.
0
Attacker Value
Unknown
CVE-2021-28213
Disclosure Date: June 11, 2021 (last updated November 28, 2024)
Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.
0
Attacker Value
Unknown
CVE-2021-28211
Disclosure Date: June 11, 2021 (last updated February 22, 2025)
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
0