Known Vulnerabilities for Edk Ii by Tianocore
Listed below are 10 of the newest known vulnerabilities associated with "Edk Ii" by "Tianocore".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-28216 | BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Suppor... | 7.8 - HIGH | 2021-08-05 | 2021-08-16 |
| CVE-2019-11098 | Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of ... | 6.8 - MEDIUM | 2021-07-14 | 2021-07-20 |
| CVE-2019-0161 | Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access. | 5.5 - MEDIUM | 2019-03-27 | 2023-11-07 |
| CVE-2019-0160 | Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege an... | 9.8 - CRITICAL | 2019-03-27 | 2023-11-07 |
| CVE-2018-12182 | Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of... | 6.7 - MEDIUM | 2019-03-27 | 2023-11-07 |
| CVE-2018-12181 | Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation o... | 6 - MEDIUM | 2019-03-27 | 2023-11-07 |
| CVE-2018-12180 | Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege... | 8.8 - HIGH | 2019-03-27 | 2023-11-07 |
| CVE-2018-12179 | Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privi... | 7.8 - HIGH | 2019-03-27 | 2023-11-07 |
| CVE-2018-12178 | Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or ... | 9.1 - CRITICAL | 2019-03-27 | 2023-11-07 |
| CVE-2018-3613 | Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enab... | 7.8 - HIGH | 2019-03-27 | 2023-11-07 |