Vulnerability index

Browse CVEs

99 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Insydeh2o HIGH 7.0
CVE-2022-32473

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the HddPassword shared buffer used by SMM and non-SMM code co…

Fix: 5.2.05.27.27 / 5.3.05.36.27+
Fix from $1,950 2023-02-15
Insydeh2o HIGH 7.0
CVE-2022-32476

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the AhciBusDxe shared buffer used by SMM and non-SMM code cou…

Fix: 5.2.05.27.27 / 5.3.05.36.27+
Fix from $1,950 2023-02-15
Insydeh2o HIGH 7.0
CVE-2022-32953

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the SdHostDriver buffer used by SMM and non-SMM code could ca…

Fix: 5.2.05.27.27 / 5.3.05.36.27+
Fix from $1,950 2023-02-15
Insydeh2o HIGH 7.0
CVE-2022-32470

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the FwBlockServiceSmm shared buffer used by SMM and non-SMM c…

Fix: 5.2.05.27.27 / 5.3.05.36.27+
Fix from $1,950 2023-02-15
Insydeh2o HIGH 7.0
CVE-2022-32471

An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. The IhisiDxe driver uses the command buffer to pass input and ou…

Fix: 5.2.05.27.37 / 5.3.05.36.37+
Fix from $1,950 2023-02-15
Insydeh2o HIGH 7.0
CVE-2022-32474

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the StorageSecurityCommandDxe shared buffer used by SMM and n…

Fix: 5.0.05.09.42 / 5.1.05.17.42+
Fix from $1,950 2023-02-15
Insydeh2o HIGH 7.0
CVE-2022-32478

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the IdeBusDxe shared buffer used by SMM and non-SMM code coul…

Fix: 5.0.05.09.42 / 5.1.05.17.42+
Fix from $1,950 2023-02-15
Insydeh2o HIGH 7.0
CVE-2022-32954

An issue was discovered in Insyde InsydeH2O with kernel 5.1 through 5.5. DMA attacks on the SdMmcDevice buffer used by SMM and non-SMM code could cau…

Fix: 5.2.05.27.27 / 5.3.05.36.27+
Fix from $1,950 2023-02-15
Insydeh2o HIGH 7.0
CVE-2022-32955

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the NvmExpressDxe buffer used by SMM and non-SMM code could c…

Fix: 5.2.05.27.27 / 5.3.05.36.27+
Fix from $1,950 2023-02-15
Kernel HIGH 8.2
CVE-2022-36337

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads …

Fix: after 5.5
Fix from $1,950 2022-11-23
Kernel HIGH 7.8
CVE-2022-35407

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtilit…

Fix: after 5.5
Fix from $1,950 2022-11-22
Kernel MEDIUM 6.8
CVE-2022-35897

An stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. If the…

Fix: after 5.5
Fix from $1,600 2022-11-21
Kernel HIGH 8.2
CVE-2022-29278

Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer checks within the NvmExpressD…

Fix: 5.1.05.17.23 / 5.2.05.27.23+
Fix from $1,950 2022-11-15
Kernel HIGH 8.2
CVE-2022-29279

Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted pointer allows tampering with…

Fix: 5.0.05.09.17 / 5.1.05.17.17+
Fix from $1,950 2022-11-15
Kernel HIGH 8.2
CVE-2022-29276

SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corrupti…

Fix: 5.0.05.09.18 / 5.1.05.17.18+
Fix from $1,950 2022-11-15
Kernel HIGH 8.2
CVE-2022-29275

In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to e…

Fix: 5.1.05.17.21 / 5.2.05.27.21+
Fix from $1,950 2022-11-15
Kernel HIGH 8.2
CVE-2022-30771

Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead…

Fix: 5.1.05.17.25 / 5.2.05.27.25+
Fix from $1,950 2022-11-15
Kernel HIGH 8.2
CVE-2022-30772

Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSm…

Fix: 5.0.05.09.41 / 5.1.05.17.43+
Fix from $1,950 2022-11-15
Kernel HIGH 7.5
CVE-2022-30283

In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU proble…

Fix: 5.0.05.09.21 / 5.1.05.17.21+
Fix from $1,950 2022-11-15
Kernel HIGH 7.0
CVE-2022-33909

DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM corruption through a TOCTOU atta…

Fix: 5.2.05.27.23 / 5.3.05.36.23+
Fix from $1,950 2022-11-15
Kernel HIGH 7.0
CVE-2022-33983

DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRAM corruption through a TOCTOU…

Fix: 5.2.05.27.25 / 5.3.05.36.25+
Fix from $1,950 2022-11-15
Kernel HIGH 7.0
CVE-2022-33984

DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI handler could cause SMRAM corruption through a TOCTOU atta…

Fix: 5.2.05.27.25 / 5.3.05.36.25+
Fix from $1,950 2022-11-15
Kernel HIGH 7.0
CVE-2022-33985

DMA transactions which are targeted at input buffers used for the NvmExpressDxe software SMI handler could cause SMRAM corruption through a TOCTOU at…

Fix: 5.2.05.27.25 / 5.3.05.36.25+
Fix from $1,950 2022-11-15
Kernel MEDIUM 6.4
CVE-2022-33986

DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. DMA attacks on the parameter b…

Fix: 5.4.05.44.23 / 5.5.05.52.23+
Fix from $1,600 2022-11-15
Kernel HIGH 7.0
CVE-2022-33905

DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler could cause SMRAM corruption (a TOCTOU attack). DMA…

Fix: 5.2.05.27.23 / 5.3.05.36.23+
Fix from $1,950 2022-11-15
Kernel HIGH 7.0
CVE-2022-33908

DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM corruption through a TOCTOU att…

Fix: 5.2.05.27.25 / 5.3.05.36.25+
Fix from $1,950 2022-11-15
Kernel MEDIUM 6.4
CVE-2022-31243

Update description and links DMA transactions which are targeted at input buffers used for the software SMI handler used by the FvbServicesRuntimeDxe…

Fix: 5.2.05.27.21 / 5.3.05.36.21+
Fix from $1,600 2022-11-15
Kernel MEDIUM 6.4
CVE-2022-32267

DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM corruption (a TOCTOU attack) D…

Fix: 5.2.05.27.23 / 5.3.05.36.23+
Fix from $1,600 2022-11-15
Kernel MEDIUM 6.4
CVE-2022-33906

DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMRAM corruption through a TOCTO…

Fix: 5.2.05.27.23 / 5.3.05.36.23+
Fix from $1,600 2022-11-15
Kernel MEDIUM 6.4
CVE-2022-30774

DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been checked but before they are …

Fix: 5.2.05.27.29 / 5.3.05.36.25+
Fix from $1,600 2022-11-15