Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 407 respecto a la semana anterior
Críticas / altas1311▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.42% | — | Tianocore EDK II | 5/8/2021 | 17/6/2026 | BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE. | |
| Modificada | Media (6.8) | 0.34% | — | Tianocore EDK II | 14/7/2021 | 17/6/2026 | Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access. | |
| Modificada | Media (5.5) | 0.40% | — | Tianocore EDK II | 27/3/2019 | 17/6/2026 | Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access. | |
| Modificada | Crítica (9.8) | 1.3% | — | Tianocore EDK IIOpensuse LeapFedoraproject FedoraRedhat Enterprise Linux+4 | 27/3/2019 | 17/6/2026 | Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access. | |
| Modificada | Alta (7.8) | 0.44% | — | Tianocore EDK II | 27/3/2019 | 17/6/2026 | Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access. | |
| Modificada | Media (6.8) | 0.50% | — | Tianocore EDK II | 27/3/2019 | 17/6/2026 | Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.41% | — | Tianocore EDK II | 27/3/2019 | 17/6/2026 | Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access. | |
| Modificada | Media (6) | 0.43% | — | Tianocore EDK II | 27/3/2019 | 17/6/2026 | Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access. | |
| Modificada | Alta (8.8) | 2.3% | — | Tianocore EDK IIOpensuse Leap | 27/3/2019 | 17/6/2026 | Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access. | |
| Modificada | Alta (7.8) | 0.42% | — | Tianocore EDK II | 27/3/2019 | 17/6/2026 | Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access. | |
| Modificada | Crítica (9.1) | 2.3% | — | Tianocore EDK II | 27/3/2019 | 17/6/2026 | Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network. |