CVE-2024-38805
- EPSS 0.04%
- Veröffentlicht 12.08.2025 14:13:28
- Zuletzt bearbeitet 13.08.2025 17:34:12
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.
- EPSS 0.02%
- Veröffentlicht 07.08.2025 01:15:25
- Zuletzt bearbeitet 07.08.2025 21:26:37
EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availabil...
CVE-2024-38797
- EPSS 0.02%
- Veröffentlicht 07.04.2025 17:18:01
- Zuletzt bearbeitet 08.04.2025 18:14:17
EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/...
CVE-2025-2295
- EPSS 0.11%
- Veröffentlicht 14.03.2025 21:35:10
- Zuletzt bearbeitet 14.03.2025 22:15:11
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.
CVE-2024-12546
- EPSS 0.04%
- Veröffentlicht 11.03.2025 14:02:41
- Zuletzt bearbeitet 13.03.2025 03:15:34
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-38796
- EPSS 0.05%
- Veröffentlicht 27.09.2024 22:15:13
- Zuletzt bearbeitet 06.12.2024 14:15:20
EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or ...
- EPSS 0.03%
- Veröffentlicht 30.05.2024 21:15:09
- Zuletzt bearbeitet 07.03.2025 01:15:11
EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.
CVE-2023-49721
- EPSS 0.02%
- Veröffentlicht 14.02.2024 22:15:47
- Zuletzt bearbeitet 26.08.2025 17:19:29
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
CVE-2023-48733
- EPSS 0.01%
- Veröffentlicht 14.02.2024 22:15:47
- Zuletzt bearbeitet 26.08.2025 17:19:40
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
CVE-2023-45237
- EPSS 0.38%
- Veröffentlicht 16.01.2024 16:15:13
- Zuletzt bearbeitet 13.02.2025 18:15:30
EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.