|
223191
|
7.8 |
HIGH
Local
|
tianocore debian
|
edk2 debian_linux
|
Integer truncation in EDK II may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-787 CWE-681
Out-of-bounds Write Incorrect Conversion between Numeric Types
|
CVE-2019-14563
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223192
|
5.5 |
MEDIUM
Local
|
tianocore debian
|
edk2 debian_linux
|
Integer overflow in DxeImageVerificationHandler() EDK II may allow an authenticated user to potentially enable denial of service via local access.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2019-14562
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223193
|
7.5 |
HIGH
Network
|
tianocore
|
edk2
|
Uncontrolled resource consumption in EDK II may allow an unauthenticated user to potentially enable denial of service via network access.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2019-14559
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223194
|
4.9 |
MEDIUM
Network
|
tianocore
|
edk2
|
Improper authentication in EDK II may allow a privileged user to potentially enable information disclosure via network access.
|
CWE-287
Improper Authentication
|
CVE-2019-14553
|
2024-11-21 13:26 |
2020-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223195
|
5.7 |
MEDIUM
Adjacent
|
intel debian
|
bios debian_linux
|
Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to p…
|
NVD-CWE-Other
|
CVE-2019-14558
|
2024-11-21 13:26 |
2020-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223196
|
8.0 |
HIGH
Adjacent
|
intel
|
bios
|
Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable ele…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-14557
|
2024-11-21 13:26 |
2020-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223197
|
4.4 |
MEDIUM
Local
|
intel
|
bios
|
Improper initialization in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow a privileged user to potentially enable…
|
CWE-665
Improper Initialization
|
CVE-2019-14556
|
2024-11-21 13:26 |
2020-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223198
|
7.0 |
HIGH
Local
|
qualcomm
|
ipq6018_firmware kamorta_firmware mdm9205_firmware mdm9607_firmware nicobar_firmware qcs404_firmware qcs405_firmware qcs605_firmware qcs610_firmware rennell_firmware sa4…
|
u'While processing SMCInvoke asynchronous message header, message count is modified leading to a TOCTOU race condition and lead to memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdrago…
|
CWE-787 CWE-367
Out-of-bounds Write Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2019-14119
|
2024-11-21 13:26 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223199
|
7.8 |
HIGH
Local
|
qualcomm
|
bitra_firmware mdm9607_firmware qcs405_firmware saipan_firmware sc8180x_firmware sdx55_firmware sm6150_firmware sm7150_firmware sm8150_firmware sm8250_firmware sxr2130_f…
|
u'Whenever the page list is updated via privileged user, the previous list elements are freed but are not deleted from the list which results in a use after free causing an unhandled page fault excep…
|
CWE-416
Use After Free
|
CVE-2019-14117
|
2024-11-21 13:26 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223200
|
5.5 |
MEDIUM
Local
|
qualcomm
|
apq8009_firmware apq8017_firmware apq8053_firmware apq8076_firmware apq8096au_firmware apq8098_firmware kamorta_firmware mdm9150_firmware mdm9205_firmware mdm9206_firmware<…
|
u'Information disclosure issue occurs as in current logic as secure touch is released without clearing the display session which can result in user reading the secure input while touch is in non-secu…
|
CWE-459
Incomplete Cleanup
|
CVE-2019-14115
|
2024-11-21 13:26 |
2020-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|