Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Edk2 HIGH 8.8
CVE-2025-2486

The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of Se…

Patch available
Fix from $1,950 2025-11-26
Edk2 HIGH 7.5
CVE-2023-45237

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unaut…

Fix: after 202311
Fix from $1,950 2024-01-16
Edk2 HIGH 8.8
CVE-2023-45234

EDK2's Network Package is susceptible to a buffer overflow vulnerability when processing DNS Servers option from a DHCPv6 Advertise message. This vu…

Fix: after 202311
Fix from $1,950 2024-01-16
Edk2 HIGH 8.8
CVE-2023-45235

EDK2's Network Package is susceptible to a buffer overflow vulnerability when handling Server ID option from a DHCPv6 proxy Advertise messa…

Fix: after 202311
Fix from $1,950 2024-01-16
Edk2 HIGH 7.5
CVE-2023-45232

EDK2's Network Package is susceptible to an infinite loop vulnerability when parsing unknown options in the Destination Options header of IPv6. This …

Fix: after 202311
Fix from $1,950 2024-01-16
Edk2 HIGH 7.5
CVE-2023-45233

EDK2's Network Package is susceptible to an infinite lop vulnerability when parsing a PadN option in the Destination Options header of IPv6. This vu…

Fix: after 202311
Fix from $1,950 2024-01-16
Edk2 HIGH 7.5
CVE-2023-45236

EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unaut…

Fix: after 202311
Fix from $1,950 2024-01-16
Edk2 HIGH 8.8
CVE-2023-45230

EDK2's Network Package is susceptible to a buffer overflow vulnerability via a long server ID option in DHCPv6 client. This vulnerability can be exp…

Fix: after 202311
Fix from $1,950 2024-01-16
Edk2 MEDIUM 6.5
CVE-2023-45229

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing the IA_NA or IA_TA option in a DHCPv6 Advertise message…

Fix: after 202311
Fix from $1,600 2024-01-16
Edk2 MEDIUM 6.5
CVE-2023-45231

EDK2's Network Package is susceptible to an out-of-bounds read vulnerability when processing  Neighbor Discovery Redirect message. This vulnerabili…

Fix: after 202311
Fix from $1,600 2024-01-16
Edk2 HIGH 7.8
CVE-2022-36763

EDK2 is susceptible to a vulnerability in the Tcg2MeasureGptTable() function, allowing a user to trigger a heap buffer overflow via a local network. …

Fix: after 202311
Fix from $1,950 2024-01-09
Edk2 HIGH 7.8
CVE-2022-36764

EDK2 is susceptible to a vulnerability in the Tcg2MeasurePeImage() function, allowing a user to trigger a heap buffer overflow via a local network. S…

Fix: after 202311
Fix from $1,950 2024-01-09
Edk2 HIGH 7.8
CVE-2022-36765

EDK2 is susceptible to a vulnerability in the CreateHob() function, allowing a user to trigger a integer overflow to buffer overflow via a local netw…

Fix: after 202311
Fix from $1,950 2024-01-09
Edk2 CRITICAL 9.8
CVE-2021-38578

Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

Fix: after 202202
Fix from $2,300 2022-03-03
Edk2 HIGH 7.5
CVE-2021-38576

A BIOS bug in firmware for a particular PC model leaves the Platform authorization value empty. This can be used to permanently brick the TPM in mult…

Mitigation only
Fix from $1,950 2022-01-03
Edk2 HIGH 8.1
CVE-2021-38575

NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.

Fix: after 202105
Fix from $1,950 2021-12-01
Edk Ii HIGH 7.8
CVE-2021-28216

BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.

No fix yet
Fix from $1,950 2021-08-05
Edk Ii MEDIUM 6.8
CVE-2019-11098

Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of ser…

Mitigation only
Fix from $1,600 2021-07-14
Edk2 HIGH 7.8
CVE-2021-28210

An unlimited recursion in DxeCore in EDK II.

Fix: 202008+
Fix from $1,950 2021-06-11
Edk2 HIGH 7.5
CVE-2021-28213

Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.

Mitigation only
Fix from $1,950 2021-06-11
Edk2 MEDIUM 6.7
CVE-2021-28211

A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.

Patch available
Fix from $1,600 2021-06-11
Edk2 HIGH 7.8
CVE-2019-14584

Null pointer dereference in Tianocore EDK2 may allow an authenticated user to potentially enable escalation of privilege via local access.

Fix: 2020-10-21+
Fix from $1,950 2021-06-03
Edk2 HIGH 7.5
CVE-2019-14559

Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.

Mitigation only
Fix from $1,950 2020-11-23
Edk2 MEDIUM 6.8
CVE-2014-8271

Buffer overflow in the Reclaim function in Tianocore EDK2 before SVN 16280 allows physically proximate attackers to gain privileges via a long variab…

Patch available
Fix from $1,600 2020-02-06
Edk2 MEDIUM 6.8
CVE-2014-4859

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically pr…

Mitigation only
Fix from $1,600 2020-01-31
Edk2 MEDIUM 6.8
CVE-2014-4860

Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow phys…

Mitigation only
Fix from $1,600 2020-01-31
Edk2 HIGH 7.8
CVE-2017-5731

Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escalation of privilege via local a…

Fix: 2017-11-07+
Fix from $1,950 2019-10-28
Edk Ii CRITICAL 9.1
CVE-2018-12178

Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via ne…

Patch available
Fix from $2,300 2019-03-27
Edk Ii HIGH 8.8
CVE-2018-12180

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure…

Patch available
Fix from $1,950 2019-03-27
Edk Ii HIGH 7.8
CVE-2018-12179

Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclo…

Patch available
Fix from $1,950 2019-03-27