CVE-2026-12855
- EPSS 0.13%
- Veröffentlicht 09.09.2026 03:59:11
- Zuletzt bearbeitet 01.10.2026 16:17:40
Unvalidated memory boundary could result in arbitrary code execution. The vulnerability exists in the code developed specifically for HP projects.
CVE-2026-6485
- EPSS 0.12%
- Veröffentlicht 09.09.2026 03:54:01
- Zuletzt bearbeitet 10.09.2026 15:17:39
UEFI BIOS embedded Shell could be used to bypass Secure Boot via shell commands or startup scripts.
CVE-2021-38489
- EPSS 0.12%
- Veröffentlicht 03.09.2026 02:25:11
- Zuletzt bearbeitet 03.09.2026 18:09:03
HDD password plaintext is stored in a UEFI variable.
CVE-2021-43614
- EPSS 0.13%
- Veröffentlicht 03.09.2026 02:15:34
- Zuletzt bearbeitet 03.09.2026 18:09:03
Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.
CVE-2021-43613
- EPSS 0.11%
- Veröffentlicht 03.09.2026 02:05:35
- Zuletzt bearbeitet 03.09.2026 18:09:03
An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
CVE-2026-9805
- EPSS 0.12%
- Veröffentlicht 26.08.2026 01:00:25
- Zuletzt bearbeitet 31.08.2026 19:27:23
SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow.
CVE-2025-12053
- EPSS 0.15%
- Veröffentlicht 14.01.2026 01:27:11
- Zuletzt bearbeitet 15.04.2026 00:35:42
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
CVE-2025-12052
- EPSS 0.15%
- Veröffentlicht 14.01.2026 01:23:54
- Zuletzt bearbeitet 15.04.2026 00:35:42
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
CVE-2025-12051
- EPSS 0.16%
- Veröffentlicht 14.01.2026 01:17:54
- Zuletzt bearbeitet 15.04.2026 00:35:42
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.
CVE-2025-12050
- EPSS 0.16%
- Veröffentlicht 14.01.2026 01:15:49
- Zuletzt bearbeitet 15.04.2026 00:35:42
The drivers in the tool packages use RTL_QUERY_REGISTRY_DIRECT flag to read a registry value to which an untrusted user-mode application may be able to cause a buffer overflow.