Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown
CVE-2023-48733
Disclosure Date: February 14, 2024 (last updated February 15, 2024)
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
0
Attacker Value
Unknown
CVE-2021-38577
Disclosure Date: March 03, 2022 (last updated November 08, 2023)
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
0
Attacker Value
Unknown
CVE-2021-28216
Disclosure Date: August 05, 2021 (last updated February 23, 2025)
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
0
Attacker Value
Unknown
CVE-2019-11098
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
0
Attacker Value
Unknown
CVE-2018-12183
Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
0
Attacker Value
Unknown
CVE-2018-12179
Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
0
Attacker Value
Unknown
CVE-2018-12182
Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
0
Attacker Value
Unknown
CVE-2018-3613
Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
0
Attacker Value
Unknown
CVE-2019-0160
Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
0
Attacker Value
Unknown
CVE-2018-12178
Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.
0