CVE-2024-52880
- EPSS 0.03%
- Veröffentlicht 15.05.2025 00:00:00
- Zuletzt bearbeitet 29.07.2025 13:09:06
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before vers...
CVE-2024-49200
- EPSS 0.04%
- Veröffentlicht 15.04.2025 22:15:15
- Zuletzt bearbeitet 30.04.2025 16:41:11
An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM ...
CVE-2024-25078
- EPSS 0.09%
- Veröffentlicht 15.05.2024 14:15:08
- Zuletzt bearbeitet 29.07.2025 20:02:06
A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: ...
CVE-2023-47252
- EPSS 0.13%
- Veröffentlicht 26.04.2024 03:15:06
- Zuletzt bearbeitet 29.07.2025 23:30:00
An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering. The PNP-related SMI sub-functions do not verify data size before gettin...
CVE-2022-46897
- EPSS 0.05%
- Veröffentlicht 22.04.2024 18:15:07
- Zuletzt bearbeitet 29.07.2025 20:43:39
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The CapsuleIFWUSmm driver does not check the return value from a method or function. This can prevent it from detecting unexpected states and conditions.
CVE-2023-28468
- EPSS 0.04%
- Veröffentlicht 03.08.2023 15:15:20
- Zuletzt bearbeitet 21.11.2024 07:55:09
An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attacker to interact with the SPI flash at run-time from the OS.
CVE-2022-36337
- EPSS 0.12%
- Veröffentlicht 23.11.2022 03:15:10
- Zuletzt bearbeitet 25.04.2025 21:15:32
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Control of a UEFI variable under the OS can cause this overflow when rea...
CVE-2022-35407
- EPSS 0.09%
- Veröffentlicht 22.11.2022 02:15:09
- Zuletzt bearbeitet 29.04.2025 16:15:23
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An attacker can change the values of certain UEFI variables. If the size...
CVE-2022-35897
- EPSS 0.14%
- Veröffentlicht 21.11.2022 17:15:25
- Zuletzt bearbeitet 30.04.2025 16:15:21
An stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. If the attacker modifies specific UEFI variables, it can cause a stack overflow, leading to arbitrary code ...
CVE-2022-29279
- EPSS 0.05%
- Veröffentlicht 15.11.2022 22:15:11
- Zuletzt bearbeitet 30.04.2025 15:15:52
Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice. This issue was discovered by Insyde during secu...