Known Vulnerabilities for EDK II by TianoCore
Listed below are 10 of the newest known vulnerabilities associated with "EDK II" by "TianoCore".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-28216 json | BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Suppor... | 7.8 - HIGH | 2021-08-05 | 2021-08-16 |
| CVE-2019-11098 json | Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of ... | 6.8 - MEDIUM | 2021-07-14 | 2021-07-20 |
| CVE-2019-0161 json | Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access. | 5.5 - MEDIUM | 2019-03-27 | 2023-11-07 |
| CVE-2019-0160 json | Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege an... | 9.8 - CRITICAL | 2019-03-27 | 2023-11-07 |
| CVE-2018-12183 json | Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, informa... | 6.8 - MEDIUM | 2019-03-27 | 2023-11-07 |
| CVE-2018-12182 json | Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of... | 6.7 - MEDIUM | 2019-03-27 | 2023-11-07 |
| CVE-2018-12181 json | Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation o... | 6 - MEDIUM | 2019-03-27 | 2023-11-07 |
| CVE-2018-12180 json | Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege... | 8.8 - HIGH | 2019-03-27 | 2023-11-07 |
| CVE-2018-12179 json | Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privi... | 7.8 - HIGH | 2019-03-27 | 2023-11-07 |
| CVE-2018-12178 json | Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or ... | 9.1 - CRITICAL | 2019-03-27 | 2023-11-07 |