|
222651
|
8.0 |
HIGH
Adjacent
|
tianocore debian
|
edk2 debian_linux
|
Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.
|
CWE-416
Use After Free
|
CVE-2019-14586
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222652
|
7.8 |
HIGH
Local
|
tianocore debian
|
edk2 debian_linux
|
Logic issue in DxeImageVerificationHandler() for EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
|
NVD-CWE-noinfo
|
CVE-2019-14575
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222653
|
7.8 |
HIGH
Local
|
tianocore debian
|
edk2 debian_linux
|
Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-787 CWE-681
Out-of-bounds Write Incorrect Conversion between Numeric Types
|
CVE-2019-14563
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222654
|
5.5 |
MEDIUM
Local
|
tianocore debian
|
edk2 debian_linux
|
Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14562
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222655
|
7.5 |
HIGH
Network
|
tianocore
|
edk2
|
Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-14559
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222656
|
4.9 |
MEDIUM
Network
|
tianocore
|
edk2
|
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
|
CWE-287
Improper Authentication
|
CVE-2019-14553
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222657
|
5.7 |
MEDIUM
Adjacent
|
intel debian
|
bios debian_linux
|
Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to p…
|
NVD-CWE-Other
|
CVE-2019-14558
|
2024-11-21 13:26 |
2020-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222658
|
8.0 |
HIGH
Adjacent
|
intel
|
bios
|
Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable ele…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-14557
|
2024-11-21 13:26 |
2020-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222659
|
4.4 |
MEDIUM
Local
|
intel
|
bios
|
Improper initialization in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow a privileged user to potentially enable…
|
CWE-665
Improper Initialization
|
CVE-2019-14556
|
2024-11-21 13:26 |
2020-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222660
|
7.0 |
HIGH
Local
|
qualcomm
|
ipq6018_firmware kamorta_firmware mdm9205_firmware mdm9607_firmware nicobar_firmware qcs404_firmware qcs405_firmware qcs605_firmware qcs610_firmware rennell_firmware sa4…
|
u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition and lead to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdrago…
|
CWE-787 CWE-367
Out-of-bounds Write Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-14119
|
2024-11-21 13:26 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|