CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

tianocore

edk_ii

11 known vulnerabilities · sorted by CVSS score

CVE-2019-0160
CRITICAL9.8

Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.

tianocore / edk_ii+11
Network
Published Mar 27, 2019
CVE-2018-12178
CRITICAL9.1

Buffer overflow in network stack for EDK II may allow unprivileged user to potentially enable escalation of privilege and/or denial of service via network.

tianocore / edk_ii
Network
Published Mar 27, 2019
CVE-2018-12180
HIGH8.8

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

tianocore / edk_ii+1
Network
Published Mar 27, 2019
CVE-2018-3613
HIGH7.8

Logic issue in variable service module for EDK II/UDK2018/UDK2017/UDK2015 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

tianocore / edk_ii+2
Local
Published Mar 27, 2019
CVE-2021-28216
HIGH7.8

BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.

tianocore / edk_ii
Local
Published Aug 5, 2021
CVE-2018-12179
HIGH7.8

Improper configuration in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

tianocore / edk_ii
Local
Published Mar 27, 2019
CVE-2018-12183
MEDIUM6.8

Stack overflow in DxeCore for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

tianocore / edk_ii
Physical
Published Mar 27, 2019
CVE-2019-11098
MEDIUM6.8

Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.

tianocore / edk_ii
Physical
Published Jul 14, 2021
CVE-2018-12182
MEDIUM6.7

Insufficient memory write check in SMM service for EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via local access.

tianocore / edk_ii
Local
Published Mar 27, 2019
CVE-2018-12181
MEDIUM6.0

Stack overflow in corrupted bmp for EDK II may allow unprivileged user to potentially enable denial of service or elevation of privilege via local access.

tianocore / edk_ii
Local
Published Mar 27, 2019
CVE-2019-0161
MEDIUM5.5

Stack overflow in XHCI for EDK II may allow an unauthenticated user to potentially enable denial of service via local access.

tianocore / edk_ii
Local
Published Mar 27, 2019