Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2023-48733

Disclosure Date: February 14, 2024 (last updated February 15, 2024)
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
0
Attacker Value
Unknown

CVE-2021-38577

Disclosure Date: March 03, 2022 (last updated November 08, 2023)
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All references and descriptions in this candidate have been removed to prevent accidental usage.
0
Attacker Value
Unknown

CVE-2021-28216

Disclosure Date: August 05, 2021 (last updated February 23, 2025)
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
Attacker Value
Unknown

CVE-2019-11098

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
Attacker Value
Unknown

CVE-2018-12183

Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
0
Attacker Value
Unknown

CVE-2018-12179

Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
0
Attacker Value
Unknown

CVE-2018-12182

Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
0
Attacker Value
Unknown

CVE-2018-3613

Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
0
Attacker Value
Unknown

CVE-2019-0160

Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
Attacker Value
Unknown

CVE-2018-12178

Disclosure Date: March 27, 2019 (last updated November 08, 2023)
Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.
0