cbcvebase.

Tianocore Edk2 vulnerabilities

52 known vulnerabilities affecting tianocore/edk2.

Total CVEs
52
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH27MEDIUM21LOW1

Vulnerabilities

Page 3 of 3
CVE-2024-38798P4MEDIUMCVSS 5.8fixed in edk2-stable2025112025-12-09
CVE-2024-38798 [MEDIUM] CWE-200 CVE-2024-38798: EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information EDK2 contains a vulnerability in BIOS where an attacker may cause “Exposure of Sensitive Information to an Unauthorized Actor” by local access. Successful exploitation of this vulnerability will lead to possible information disclosure or escalation of privilege and impact Confidentiality.
nvd
CVE-2019-14553P4MEDIUMCVSS 4.9≥ 0, < 0~20190828.37eef910-42020-11-23
CVE-2019-14553 [MEDIUM] CVE-2019-14553: Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
osv
CVE-2019-14587P4MEDIUMCVSS 6.5≥ 0, < 0~20200229.4c0f6e34-12020-11-23
CVE-2019-14587 [MEDIUM] CVE-2019-14587: Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access Logic issue EDK II may allow an unauthenticated user to potentially enable denial of service via adjacent access.
osv
CVE-2018-12181P4MEDIUMCVSS 6.0≥ 0, < 0~20181115.85588389-32019-03-27
CVE-2018-12181 [MEDIUM] CVE-2018-12181: Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local acc Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.
osv
CVE-2019-14558P4MEDIUMCVSS 5.7≥ 0, < 0~20200229.4c0f6e34-12020-10-05
CVE-2019-14558 [MEDIUM] CVE-2019-14558: Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Serie Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable denial of service via adjacent access.
osv
CVE-2019-0161P4MEDIUMCVSS 5.5≥ 0, < 0~20160408.ffea0a2c-2ubuntu0.2+esm3≥ 0, < 0~20180205.c0d9813c-2ubuntu0.3+esm2+2 more2024-10-10
CVE-2019-0161 [MEDIUM] edk2 vulnerabilities edk2 vulnerabilities It was discovered that EDK II did not check the buffer length in XHCI, which could lead to a stack overflow. A local attacker could potentially use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-0161) Laszlo Ersek discovered that EDK II incorrectly handled recursion. A remote attacker could possibly use this issue to cause EDK II to consume resources, leading to
osv
CVE-2024-1298P4MEDIUMCVSS 6.0fixed in edk2-stable2024052024-05-30
CVE-2024-1298 [MEDIUM] CWE-369 CVE-2024-1298: EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Z EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.
nvdosv
CVE-2024-38797P4MEDIUMCVSS 4.6≤ edk2-stable2024082025-04-07
CVE-2024-38797 [MEDIUM] CWE-125 CVE-2024-38797: EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.
nvdosv
CVE-2024-13176P4MEDIUMCVSS 4.1≥ 0, < 2025.02-8+deb13u1≥ 0, < 2025.02-92025-01-20
CVE-2024-13176 [MEDIUM] CVE-2024-13176: Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local acces
osv
CVE-2019-14562P4MEDIUMCVSS 5.5≥ 0, < 2020.05-42020-11-23
CVE-2019-14562 [MEDIUM] CVE-2019-14562: Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
osv
CVE-2025-2295P4LOWCVSS 3.5≤ edk2-stable2025022025-03-14
CVE-2025-2295 [LOW] CWE-190 CVE-2025-2295: EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by ne EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.
nvdosv
CVE-2021-28210HIGHCVSS 7.8≥ 0, < 0~20191122.bd85bf54-2ubuntu3.22021-04-20
CVE-2021-28210 [HIGH] edk2 vulnerabilities edk2 vulnerabilities Laszlo Ersek discovered that EDK II incorrectly handled recursion. A remote attacker could possibly use this issue to cause EDK II to consume resources, leading to a denial of service. (CVE-2021-28210) Satoshi Tanda discovered that EDK II incorrectly handled decompressing certain images. A remote attacker could use this issue to cause EDK II to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-
osv
Tianocore Edk2 vulnerabilities | cvebase