VYPR

Sgx SDK

by Intel

CVEs (16)

  • CVE-2020-0561HigFeb 13, 2020
    risk 0.51cvss 7.8epss 0.00

    Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-14566HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.

  • CVE-2019-14565HigNov 14, 2019
    risk 0.51cvss 7.8epss 0.00

    Insufficient initialization in Intel(R) SGX SDK Windows versions 2.4.100.51291 and earlier, and Linux versions 2.6.100.51363 and earlier, may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.

  • CVE-2018-18098HigJan 10, 2019
    risk 0.47cvss 7.3epss 0.00

    Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privilege via local access.

  • CVE-2021-0186MedNov 17, 2021
    risk 0.44cvss 6.7epss 0.00

    Improper input validation in the Intel(R) SGX SDK applications compiled for SGX2 enabled processors may allow a privileged user to potentially escalation of privilege via local access.

  • CVE-2022-21166MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.06

    Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-21127MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.05

    Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-21125MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.06

    Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-21123MedJun 15, 2022
    risk 0.36cvss 5.5epss 0.06

    Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2021-0001MedJun 9, 2021
    risk 0.31cvss 4.7epss 0.00

    Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.

  • CVE-2018-3626MedMar 20, 2018
    risk 0.31cvss 4.7epss 0.00

    Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.

  • CVE-2024-34776MedNov 13, 2024
    risk 0.29cvss 4.5epss 0.00

    Out-of-bounds write in some Intel(R) SGX SDK software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2025-32004LowAug 12, 2025
    risk 0.25cvss 3.9epss 0.00

    Improper input validation in the Intel Edger8r Tool for some Intel(R) SGX SDK may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-26841LowFeb 16, 2023
    risk 0.16cvss 2.5epss 0.00

    Insufficient control flow management for the Intel(R) SGX SDK software for Linux before version 2.16.100.1 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-26509LowFeb 16, 2023
    risk 0.16cvss 2.5epss 0.00

    Improper conditions check in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information disclosure via local access.

  • CVE-2022-27499LowNov 11, 2022
    risk 0.16cvss 2.5epss 0.00

    Premature release of resource during expected lifetime in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information disclosure via local access.