Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-38797

Опубликовано: 07 апр. 2025
Источник: nvd
CVSS3: 4.6
EPSS Низкий

Описание

EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.

EPSS

Процентиль: 11%
0.00036
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 4.6
ubuntu
10 месяцев назад

EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.

CVSS3: 4.6
redhat
10 месяцев назад

EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.

CVSS3: 4.6
debian
10 месяцев назад

EDK2 contains a vulnerability in the HashPeImageByType(). A user may c ...

CVSS3: 4.6
fstec
10 месяцев назад

Уязвимость функции HashPeImageByType() библиотеки Tianocore EDK2, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

oracle-oval
около 1 месяца назад

ELSA-2025-28047: edk2 security update (IMPORTANT)

EPSS

Процентиль: 11%
0.00036
Низкий

4.6 Medium

CVSS3

Дефекты

CWE-125