Tianocore Edk Ii vulnerabilities
7 known vulnerabilities affecting tianocore/edk_ii.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2021-38578CRITICALCVSS 9.8vedk2-stable2022082022-03-03
CVE-2021-38578 [CRITICAL] CWE-124 CVE-2021-38578: Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
cvelistv5nvd
CVE-2021-38576HIGHCVSS 7.5vedk2-stable202105, edk2-stable202102, edk2-stable202011, edk2-stable202008, edk2-stable202005, edk2-stable202002, edk2-stable201911, edk2-stable201908, edk2-stable201905, edk2-stable201903, edk2-stable201811, edk2-stable2018082022-01-03
CVE-2021-38576 [HIGH] CVE-2021-38576: A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty
A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in multiple ways, as well as to non-permanently DoS the system.
cvelistv5
CVE-2021-38575HIGHCVSS 8.1≥ unspecified, ≤ edk2-stable2021052021-12-01
CVE-2021-38575 [HIGH] CWE-124 CVE-2021-38575: NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
cvelistv5nvd
CVE-2021-28216HIGHCVSS 7.8vEDK II Master2021-08-05
CVE-2021-28216 [HIGH] CWE-587 CVE-2021-28216: BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePer
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
cvelistv5nvd
CVE-2021-28213HIGHCVSS 7.5vedk2-stable2019052021-06-11
CVE-2021-28213 [HIGH] CVE-2021-28213: Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.
Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.
cvelistv5nvd
CVE-2021-28211MEDIUMCVSS 6.7vedk2-stable2020082021-06-11
CVE-2021-28211 [MEDIUM] CWE-122 CVE-2021-28211: A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
cvelistv5nvd
CVE-2018-3613HIGHCVSS 7.8vudk2015vudk2017+1 more2019-03-27
CVE-2018-3613 [HIGH] CVE-2018-3613: Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated
Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.
nvd