Recent CVEs
CVE-2021-38578
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
HIGH
Mar 03, 2022
CVE-2021-38575
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
UNKNOWN
Dec 01, 2021
CVE-2021-28216
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
UNKNOWN
Aug 05, 2021
CVE-2021-28211
A heap overflow in LzmaUefiDecompressGetInfo function in EDK II.
UNKNOWN
Jun 11, 2021
CVE-2021-28210
An unlimited recursion in DxeCore in EDK II.
UNKNOWN
Jun 11, 2021
CVE-2021-28213
Example EDK2 encrypted private key in the IpSecDxe.efi present potential security risks.
UNKNOWN
Jun 11, 2021