Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14586

Опубликовано: 16 фев. 2020
Источник: redhat
CVSS3: 4.6
EPSS Низкий

Описание

Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7ovmfNot affected
Red Hat Enterprise Linux 8edk2Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1833340edk2: potential use-after-free due to the original configuration runtime memory is freed but it is still exposed to the OS runtime

EPSS

Процентиль: 34%
0.00135
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 8
ubuntu
около 5 лет назад

Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.

CVSS3: 8
nvd
около 5 лет назад

Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.

CVSS3: 8
debian
около 5 лет назад

Use after free vulnerability in EDK II may allow an authenticated user ...

github
больше 3 лет назад

Use after free vulnerability in EDK II may allow an authenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via adjacent access.

EPSS

Процентиль: 34%
0.00135
Низкий

4.6 Medium

CVSS3