All 16 CVE vulnerabilities found in Extensible Firmware Interface Development Kit (EDK II), with AI-generated Chinese analysis, references, and POCs.
This page catalogs Common Vulnerabilities and Exposures associated with the Extensible Firmware Interface Development Kit, a widely used framework for developing UEFI and SMBIOS firmware components. It aggregates security issues identified in the EDK II codebase, tracking flaws that may impact firmware integrity, boot security, and system stability. The collection includes vulnerabilities reported between 2010 and 2024, covering a broad spectrum of issues from memory corruption and buffer overflows to improper access controls and cryptographic weaknesses. These flaws often arise during firmware module development or when integrating third-party libraries into the EDK II environment, potentially allowing attackers to bypass security features, execute arbitrary code, or cause denial-of-service conditions. By reviewing this aggregation, security professionals and firmware developers can track vendor advisories related to specific EDK II releases, gaining insight into how particular weakness classes have manifested over time. This resource helps users understand the historical context of security defects within the framework, facilitating better risk assessment and mitigation strategies. It also serves as a reference for understanding the vulnerability history of the product, enabling teams to identify patterns, prioritize patches, and improve secure coding practices. The data supports informed decision-making for organizations deploying UEFI-based systems, ensuring they remain aware of known risks in their firmware infrastructure.
Vendor: Extensible Firmware Interface Development Kit (EDK II)
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2019-14587 | EDK2 安全漏洞 | 6.5 | - | 2020-11-23 |
| CVE-2019-14586 | EDK2 资源管理错误漏洞 | 8.0 | - | 2020-11-23 |
| CVE-2019-14575 | EDK2 安全漏洞 | 7.8 | - | 2020-11-23 |
| CVE-2019-14563 | EDK2 输入验证错误漏洞 | 7.8 | - | 2020-11-23 |
| CVE-2019-14562 | EDK2 输入验证错误漏洞 | 5.5 | - | 2020-11-23 |
| CVE-2019-14559 | EDK2 资源管理错误漏洞 | 7.5 | - | 2020-11-23 |
| CVE-2019-14553 | EDK2 授权问题漏洞 | 4.9 | - | 2020-11-23 |
| CVE-2019-0161 | XHCI for EDK2 缓冲区错误漏洞 | 5.5 | - | 2019-03-27 |
| CVE-2018-12181 | EDK2 缓冲区错误漏洞 | 6.0 | - | 2019-03-27 |
| CVE-2018-12180 | EDK2 缓冲区错误漏洞 | 9.8 | - | 2019-03-27 |
| CVE-2018-12179 | EDK2 配置错误漏洞 | 7.8 | - | 2019-03-27 |
| CVE-2019-0160 | EDK2 缓冲区错误漏洞 | 9.8 | - | 2019-03-27 |
| CVE-2018-12178 | EDK2 安全漏洞 | 9.8 | - | 2019-03-27 |
| CVE-2018-12182 | EDK2 安全漏洞 | 7.8 | - | 2019-03-27 |
| CVE-2018-12183 | EDK2 缓冲区错误漏洞 | 7.8 | - | 2019-03-27 |
| CVE-2018-3613 | EDK2 权限许可和访问控制问题漏洞 | 7.8 | - | 2019-03-27 |
All 16 known CVE vulnerabilities affecting Extensible Firmware Interface Development Kit (EDK II) with full Chinese analysis, references, and POCs where available.