Tianocore Edk2 vulnerabilities
52 known vulnerabilities affecting tianocore/edk2.
Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH27MEDIUM21LOW1
Vulnerabilities
Page 3 of 3
CVE-2024-38798P4MEDIUMCVSS 5.8fixed in edk2-stable2025112025-12-09
CVE-2024-38798 [MEDIUM] CWE-200 CVE-2024-38798: EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information
EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to
possible information disclosure or escalation of privilege
and impact Confidentiality.
nvd
CVE-2019-14553P4MEDIUMCVSS 4.9≥ 0, < 0~20190828.37eef910-42020-11-23
CVE-2019-14553 [MEDIUM] CVE-2019-14553: Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
osv
CVE-2019-14587P4MEDIUMCVSS 6.5≥ 0, < 0~20200229.4c0f6e34-12020-11-23
CVE-2019-14587 [MEDIUM] CVE-2019-14587: Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access
Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
osv
CVE-2018-12181P4MEDIUMCVSS 6.0≥ 0, < 0~20181115.85588389-32019-03-27
CVE-2018-12181 [MEDIUM] CVE-2018-12181: Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local acc
Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.
osv
CVE-2019-14558P4MEDIUMCVSS 5.7≥ 0, < 0~20200229.4c0f6e34-12020-10-05
CVE-2019-14558 [MEDIUM] CVE-2019-14558: Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Serie
Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
osv
CVE-2019-0161P4MEDIUMCVSS 5.5≥ 0, < 0~20160408.ffea0a2c-2ubuntu0.2+esm3≥ 0, < 0~20180205.c0d9813c-2ubuntu0.3+esm2+2 more2024-10-10
CVE-2019-0161 [MEDIUM] edk2 vulnerabilities
edk2 vulnerabilities
It was discovered that EDK II did not check the buffer length in XHCI,
which could lead to a stack overflow. A local attacker could potentially
use this issue to cause a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-0161)
Laszlo Ersek discovered that EDK II incorrectly handled recursion. A
remote attacker could possibly use this issue to cause EDK II to consume
resources, leading to
osv
CVE-2024-1298P4MEDIUMCVSS 6.0fixed in edk2-stable2024052024-05-30
CVE-2024-1298 [MEDIUM] CWE-369 CVE-2024-1298: EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Z
EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.
nvdosv
CVE-2024-38797P4MEDIUMCVSS 4.6≤ edk2-stable2024082025-04-07
CVE-2024-38797 [MEDIUM] CWE-125 CVE-2024-38797: EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when
EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.
nvdosv
CVE-2024-13176P4MEDIUMCVSS 4.1≥ 0, < 2025.02-8+deb13u1≥ 0, < 2025.02-92025-01-20
CVE-2024-13176 [MEDIUM] CVE-2024-13176: Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation
Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local acces
osv
CVE-2019-14562P4MEDIUMCVSS 5.5≥ 0, < 2020.05-42020-11-23
CVE-2019-14562 [MEDIUM] CVE-2019-14562: Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access
Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
osv
CVE-2025-2295P4LOWCVSS 3.5≤ edk2-stable2025022025-03-14
CVE-2025-2295 [LOW] CWE-190 CVE-2025-2295: EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by ne
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.
nvdosv
CVE-2021-28210HIGHCVSS 7.8≥ 0, < 0~20191122.bd85bf54-2ubuntu3.22021-04-20
CVE-2021-28210 [HIGH] edk2 vulnerabilities
edk2 vulnerabilities
Laszlo Ersek discovered that EDK II incorrectly handled recursion. A
remote attacker could possibly use this issue to cause EDK II to consume
resources, leading to a denial of service. (CVE-2021-28210)
Satoshi Tanda discovered that EDK II incorrectly handled decompressing
certain images. A remote attacker could use this issue to cause EDK II to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2021-
osv
← Previous3 / 3