Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-4860

Опубликовано: 31 янв. 2020
Источник: nvd
CVSS3: 6.8
CVSS2: 7.2
EPSS Низкий

Описание

Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tianocore:edk2:-:*:*:*:*:*:*:*

EPSS

Процентиль: 11%
0.00037
Низкий

6.8 Medium

CVSS3

7.2 High

CVSS2

Дефекты

CWE-190

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 6 лет назад

Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase.

CVSS3: 6.8
debian
около 6 лет назад

Multiple integer overflows in the Pre-EFI Initialization (PEI) boot ph ...

github
больше 3 лет назад

Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase.

EPSS

Процентиль: 11%
0.00037
Низкий

6.8 Medium

CVSS3

7.2 High

CVSS2

Дефекты

CWE-190