Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-4859

Опубликовано: 31 янв. 2020
Источник: nvd
CVSS3: 6.8
CVSS2: 7.2
EPSS Низкий

Описание

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tianocore:edk2:-:*:*:*:*:*:*:*

EPSS

Процентиль: 12%
0.00039
Низкий

6.8 Medium

CVSS3

7.2 High

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 6 лет назад

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

CVSS3: 6.8
debian
около 6 лет назад

Integer overflow in the Drive Execution Environment (DXE) phase in the ...

github
больше 3 лет назад

Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data.

EPSS

Процентиль: 12%
0.00039
Низкий

6.8 Medium

CVSS3

7.2 High

CVSS2

Дефекты

CWE-190