Known Vulnerabilities for Edk2 by Tianocore
Listed below are 10 of the newest known vulnerabilities associated with "Edk2" by "Tianocore".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-38578 | Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. | 9.8 - CRITICAL | 2022-03-03 | 2023-08-02 |
| CVE-2021-38577 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This CVE has been rejected as it was incorrectly assigned. All referen... | Not Provided | 2022-03-03 | 2023-11-07 |
| CVE-2021-38576 | A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanent... | 7.5 - HIGH | 2022-01-03 | 2022-01-13 |
| CVE-2021-38575 | NetworkPkg/IScsiDxe has remotely exploitable buffer overflows. | 8.1 - HIGH | 2021-12-01 | 2023-11-07 |
| CVE-2021-28213 | Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks. | 7.5 - HIGH | 2021-06-11 | 2022-07-12 |
| CVE-2021-28211 | A heap overflow in LzmaUefiDecompressGetInfo function in EDK II. | 6.7 - MEDIUM | 2021-06-11 | 2021-06-22 |
| CVE-2021-28210 | An unlimited recursion in DxeCore in EDK II. | 7.8 - HIGH | 2021-06-11 | 2021-06-24 |
| CVE-2019-14562 | Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of serv... | 5.5 - MEDIUM | 2020-11-23 | 2022-01-01 |
| CVE-2019-14559 | Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via net... | 7.5 - HIGH | 2020-11-23 | 2022-01-01 |
| CVE-2019-14553 | Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access... | 4.9 - MEDIUM | 2020-11-23 | 2020-11-25 |