cbcvebase.

Debian Edk2 vulnerabilities

47 known vulnerabilities affecting debian/edk2.

Total CVEs
47
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH18MEDIUM19LOW9

Vulnerabilities

Page 1 of 3
CVE-2019-0160P3LOWCVSS 9.8fixed in edk2 0~20181115.85588389-1 (bookworm)2019
CVE-2019-0160 [CRITICAL] CVE-2019-0160: edk2 - Buffer overflow in system firmware for EDK II may allow unauthenticated user to ... Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access. Scope: local bookworm: resolved (fixed in 0~20181115.85588389-1) bullseye: resolved (fixed in 0~20181115.85588389-1) forky: resolved (fixed in 0~20181115.85588389-1) sid: resolved (fixed in 0~20181115.
debian
CVE-2023-45230P3HIGHCVSS 8.3fixed in edk2 2022.11-6+deb12u1 (bookworm)2023
CVE-2023-45230 [HIGH] CVE-2023-45230: edk2 - EDK2's Network Package is susceptible to a buffer overflow vulnerability via a l... EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullseye: resolved (fixed in 2
debian
CVE-2023-45235P3HIGHCVSS 8.3fixed in edk2 2022.11-6+deb12u1 (bookworm)2023
CVE-2023-45235 [HIGH] CVE-2023-45235: edk2 - EDK2's Network Package is susceptible to a buffer overflow vulnerability when ... EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullse
debian
CVE-2023-45234P3HIGHCVSS 8.3fixed in edk2 2022.11-6+deb12u1 (bookworm)2023
CVE-2023-45234 [HIGH] CVE-2023-45234: edk2 - EDK2's Network Package is susceptible to a buffer overflow vulnerability when pr... EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality, Integrity and/or Availability. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullseye
debian
CVE-2025-2296P3HIGHCVSS 8.4fixed in edk2 2025.02-1 (forky)2025
CVE-2025-2296 [HIGH] CVE-2025-2296: edk2 - EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Inp... EDK2 contains a vulnerability in BIOS where an attacker may cause “ Improper Input Validation” by local access. Successful exploitation of this vulnerability could alter control flow in unexpected ways, potentially allowing arbitrary command execution and impacting Confidentiality, Integrity, and Availability. Scope: local bookworm: open bullseye: open forky: resolved (f
debian
CVE-2018-12178P3CRITICALCVSS 9.1fixed in edk2 0~20181115.85588389-3 (bookworm)2018
CVE-2018-12178 [CRITICAL] CVE-2018-12178: edk2 - Buffer overflow in network stack for EDK II may allow unprivileged user to poten... Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network. Scope: local bookworm: resolved (fixed in 0~20181115.85588389-3) bullseye: resolved (fixed in 0~20181115.85588389-3) forky: resolved (fixed in 0~20181115.85588389-3) sid: resolved (fixed in 0~20181115.85588389-3
debian
CVE-2018-12180P3HIGHCVSS 8.8fixed in edk2 0~20181115.85588389-3 (bookworm)2018
CVE-2018-12180 [HIGH] CVE-2018-12180: edk2 - Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user ... Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access. Scope: local bookworm: resolved (fixed in 0~20181115.85588389-3) bullseye: resolved (fixed in 0~20181115.85588389-3) forky: resolved (fixed in 0~20181115.85588389-3) sid: resol
debian
CVE-2025-2486P3MEDIUMCVSS 6.7fixed in edk2 2022.11-6+deb12u1 (bookworm)2025
CVE-2025-2486 [MEDIUM] CVE-2025-2486: edk2 - The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be... The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Secure Boot constraints. Versions 2024.05-2ubuntu0.3 and 2024.02-2ubuntu0.3 disable the Shell. Some previous versions inserted a secure-boot-based decision to continue running inside the Shell itself, which is believed to be
debian
CVE-2023-45232P3HIGHCVSS 7.5fixed in edk2 2022.11-6+deb12u1 (bookworm)2023
CVE-2023-45232 [HIGH] CVE-2023-45232: edk2 - EDK2's Network Package is susceptible to an infinite loop vulnerability when par... EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullseye: resolved (fixed in 2020.11-2+
debian
CVE-2023-45233P3HIGHCVSS 7.5fixed in edk2 2022.11-6+deb12u1 (bookworm)2023
CVE-2023-45233 [HIGH] CVE-2023-45233: edk2 - EDK2's Network Package is susceptible to an infinite lop vulnerability when pars... EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Availability. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullseye: resolved (fixed in 2020.11-2+deb
debian
CVE-2021-38575P3HIGHCVSS 8.1fixed in edk2 2021.08-1 (bookworm)2021
CVE-2021-38575 [HIGH] CVE-2021-38575: edk2 - NetworkPkg/IScsiDxe has remotely exploitable buffer overflows. NetworkPkg/IScsiDxe has remotely exploitable buffer overflows. Scope: local bookworm: resolved (fixed in 2021.08-1) bullseye: resolved (fixed in 2020.11-2+deb11u3) forky: resolved (fixed in 2021.08-1) sid: resolved (fixed in 2021.08-1) trixie: resolved (fixed in 2021.08-1)
debian
CVE-2023-45236P3MEDIUMCVSS 5.8fixed in edk2 2024.05-1 (forky)2023
CVE-2023-45236 [MEDIUM] CVE-2023-45236: edk2 - EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Numb... EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2024.05-1) sid: resolved (fixed in 2024.05-1) trixie: resolved (fixed in 2024.05-1)
debian
CVE-2023-45237P3MEDIUMCVSS 5.3fixed in edk2 2024.05-1 (forky)2023
CVE-2023-45237 [MEDIUM] CVE-2023-45237: edk2 - EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Numb... EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2024.05-1) sid: resolved (fixed in 2024.05-1) trixie: resolved (fixed in 2024.05-1)
debian
CVE-2021-38578P3HIGHCVSS 7.4fixed in edk2 2022.11-1 (bookworm)2021
CVE-2021-38578 [HIGH] CVE-2021-38578: edk2 - Existing CommBuffer checks in SmmEntryPoint will not catch underflow when comput... Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. Scope: local bookworm: resolved (fixed in 2022.11-1) bullseye: resolved (fixed in 2020.11-2+deb11u3) forky: resolved (fixed in 2022.11-1) sid: resolved (fixed in 2022.11-1) trixie: resolved (fixed in 2022.11-1)
debian
CVE-2022-36763P3HIGHCVSS 7.0fixed in edk2 2022.11-6+deb12u1 (bookworm)2022
CVE-2022-36763 [HIGH] CVE-2022-36763: edk2 - EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, al... EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullseye: resolved (fixed in 2020.11
debian
CVE-2022-36765P3HIGHCVSS 7.0fixed in edk2 2022.11-6+deb12u1 (bookworm)2022
CVE-2022-36765 [HIGH] CVE-2022-36765: edk2 - EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a u... EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullseye: resolved (fixed in 20
debian
CVE-2022-36764P3HIGHCVSS 7.0fixed in edk2 2022.11-6+deb12u1 (bookworm)2022
CVE-2022-36764 [HIGH] CVE-2022-36764: edk2 - EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, all... EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. Successful exploitation of this vulnerability may result in a compromise of confidentiality, integrity, and/or availability. Scope: local bookworm: resolved (fixed in 2022.11-6+deb12u1) bullseye: resolved (fixed in 2020.11-
debian
CVE-2019-14559P3LOWCVSS 7.5fixed in edk2 0~20200229.4c0f6e34-1 (bookworm)2019
CVE-2019-14559 [HIGH] CVE-2019-14559: edk2 - Uncontrolled resource consumption in EDK II may allow an unauthenticated user to... Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access. Scope: local bookworm: resolved (fixed in 0~20200229.4c0f6e34-1) bullseye: resolved (fixed in 0~20200229.4c0f6e34-1) forky: resolved (fixed in 0~20200229.4c0f6e34-1) sid: resolved (fixed in 0~20200229.4c0f6e34-1) trixie: resolved (fi
debian
CVE-2019-14586P3HIGHCVSS 8.0fixed in edk2 0~20200229.4c0f6e34-1 (bookworm)2019
CVE-2019-14586 [HIGH] CVE-2019-14586: edk2 - Use after free vulnerability in EDK II may allow an authenticated user to potent... Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access. Scope: local bookworm: resolved (fixed in 0~20200229.4c0f6e34-1) bullseye: resolved (fixed in 0~20200229.4c0f6e34-1) forky: resolved (fixed in 0~20200229.4c0f6e34-1) sid: resolved (fix
debian
CVE-2021-38576P3HIGHCVSS 7.5fixed in edk2 2021.11-1 (bookworm)2021
CVE-2021-38576 [HIGH] CVE-2021-38576: edk2 - A BIOS bug in firmware for a particular PC model leaves the Platform authorizati... A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system. Scope: local bookworm: resolved (fixed in 2021.11-1) bullseye: resolved (fixed in 2020.11-2+deb11u3) forky: resolved (fixed in 2021.11-1) sid: resolved (fixed in 202
debian
Debian Edk2 vulnerabilities | cvebase