Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-38797

Опубликовано: 07 апр. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 4.6

Описание

EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.

РелизСтатусПримечание
devel

not-affected

2025.02-8ubuntu1
esm-apps/bionic

needs-triage

esm-apps/xenial

needs-triage

esm-infra/focal

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

released

2022.02-3ubuntu0.22.04.4
noble

released

2024.02-2ubuntu0.6
oracular

ignored

end of life, was needs-triage
plucky

released

2025.02-3ubuntu2.2
questing

not-affected

2025.02-8ubuntu1

Показывать по

EPSS

Процентиль: 11%
0.00036
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.6
redhat
10 месяцев назад

EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.

CVSS3: 4.6
nvd
10 месяцев назад

EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.

CVSS3: 4.6
debian
10 месяцев назад

EDK2 contains a vulnerability in the HashPeImageByType(). A user may c ...

CVSS3: 4.6
fstec
10 месяцев назад

Уязвимость функции HashPeImageByType() библиотеки Tianocore EDK2, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

oracle-oval
около 1 месяца назад

ELSA-2025-28047: edk2 security update (IMPORTANT)

EPSS

Процентиль: 11%
0.00036
Низкий

4.6 Medium

CVSS3