Show filters
183 Total Results
Displaying 141-150 of 183
Sort by:
Attacker Value
Unknown

CVE-2021-33115

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Attacker Value
Unknown

CVE-2021-42059

Disclosure Date: February 03, 2022 (last updated February 23, 2025)
An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.35.41, and Kernel 5.4 before 05.42.20. A stack-based buffer overflow leads toarbitrary code execution in UEFI DisplayTypeDxe DXE driver.
Attacker Value
Unknown

CVE-2020-5953

Disclosure Date: February 03, 2022 (last updated October 07, 2023)
A vulnerability exists in System Management Interrupt (SWSMI) handler of InsydeH2O UEFI Firmware code located in SWSMI handler that dereferences gRT (EFI_RUNTIME_SERVICES) pointer to call a GetVariable service, which is located outside of SMRAM. This can result in code execution in SMM (escalating privilege from ring 0 to ring -2).
Attacker Value
Unknown

CVE-2021-0071

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
Attacker Value
Unknown

CVE-2021-21572

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.
Attacker Value
Unknown

CVE-2021-21571

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering.
Attacker Value
Unknown

CVE-2021-21573

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.
Attacker Value
Unknown

CVE-2021-21574

Disclosure Date: June 24, 2021 (last updated February 22, 2025)
Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions.
Attacker Value
Unknown

CVE-2021-21556

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a stack-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.
Attacker Value
Unknown

CVE-2021-21555

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
Dell PowerEdge R640, R740, R740XD, R840, R940, R940xa, MX740c, MX840c, and T640 Server BIOS contain a heap-based buffer overflow vulnerability in systems with NVDIMM-N installed. A local malicious user with high privileges may potentially exploit this vulnerability, leading to a denial of Service, arbitrary code execution, or information disclosure in UEFI or BIOS Preboot Environment.