Vendor CVEs
Tianocore
All CVEs
53 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-14553 | Med | 0.32 | 4.9 | 0.01 | Nov 23, 2020 | Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access. | ||
| CVE-2024-38797 | Med | 0.30 | 4.6 | 0.00 | Apr 7, 2025 | EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability. | ||
| CVE-2025-2295 | Low | 0.23 | 3.5 | 0.00 | Mar 14, 2025 | EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service. |
- risk 0.32cvss 4.9epss 0.01
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
- risk 0.30cvss 4.6epss 0.00
EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.
- risk 0.23cvss 3.5epss 0.00
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.
Page 2 of 2