Edk ii
This hub aggregates every CVE we track for Edk ii, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
16
CVEs tracked
2
Critical
8
High
0
In CISA KEV
Severity distribution
HIGH8MEDIUM6CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Edk ii.
- CVE-2021-38578Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.7.4
- CVE-2021-38575NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.8.1
- CVE-2021-28216BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.7.8
- CVE-2019-11098Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical ...6.8
- CVE-2021-28211A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.6.7
- CVE-2021-28210An unlimited recursion in DxeCore in EDK II.7.8
- CVE-2021-28213Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.7.5
- CVE-2019-0161Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access.5.5
- CVE-2018-12181Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.6.0
- CVE-2018-12180Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.8.8
- CVE-2018-12179Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.7.8
- CVE-2019-0160Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.9.8
- CVE-2018-12178Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.9.1
- CVE-2018-12182Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local ac...6.7
- CVE-2018-12183Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.6.8
Product normalization is registry-driven with AI assist and human review. How it works