CVE-2024-38805
- EPSS 0.04%
- Published 12.08.2025 14:13:28
- Last modified 13.08.2025 17:34:12
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.
- EPSS 0.02%
- Published 07.08.2025 01:15:25
- Last modified 07.08.2025 21:26:37
EDK2 contains a vulnerability in BIOS where an attacker may cause “Protection Mechanism Failure” by local access. Successful exploitation of this vulnerability will lead to arbitrary code execution and impact Confidentiality, Integrity, and Availabil...
CVE-2024-38797
- EPSS 0.02%
- Published 07.04.2025 17:18:01
- Last modified 08.04.2025 18:14:17
EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/...
CVE-2025-2295
- EPSS 0.11%
- Published 14.03.2025 21:35:10
- Last modified 14.03.2025 22:15:11
EDK2 contains a vulnerability in BIOS where a user may cause an Integer Overflow or Wraparound by network means. A successful exploitation of this vulnerability may lead to denial of service.
CVE-2024-12546
- EPSS 0.04%
- Published 11.03.2025 14:02:41
- Last modified 13.03.2025 03:15:34
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-38796
- EPSS 0.05%
- Published 27.09.2024 22:15:13
- Last modified 06.12.2024 14:15:20
EDK2 contains a vulnerability in the PeCoffLoaderRelocateImage(). An Attacker may cause memory corruption due to an overflow via an adjacent network. A successful exploit of this vulnerability may lead to a loss of Confidentiality, Integrity, and/or ...
- EPSS 0.03%
- Published 30.05.2024 21:15:09
- Last modified 07.03.2025 01:15:11
EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.
CVE-2023-49721
- EPSS 0.02%
- Published 14.02.2024 22:15:47
- Last modified 26.08.2025 17:19:29
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
CVE-2023-48733
- EPSS 0.01%
- Published 14.02.2024 22:15:47
- Last modified 26.08.2025 17:19:40
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
CVE-2023-45237
- EPSS 0.38%
- Published 16.01.2024 16:15:13
- Last modified 13.02.2025 18:15:30
EDK2's Network Package is susceptible to a predictable TCP Initial Sequence Number. This vulnerability can be exploited by an attacker to gain unauthorized access and potentially lead to a loss of Confidentiality.