CVEs we hold for Tianocore
Records whose assigning authority named Tianocore as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-3770SMM IDT Privilege Escalation VulnerabilityTianoCore EDK2 CVE-2025-2296Un-verified kernel bypass Secure Boot mechanism in direct boot modeTianoCore EDK2 CVE-2024-38805iSCSI Remote Memory Corruption and Denial of ServiceTianoCore EDK2 CVE-2024-38798Uncleared password keystrokes in circular queue can lead to information disclosure or escalation of privilegeTianoCore EDK2 CVE-2024-38796Integer overflow in PeCoffLoaderRelocateImageTianoCore EDK2 CVE-2024-1298Integer Overflow caused by divide by zero during S3 suspensionTianoCore edk2 CVE-2023-45237Use of a Weak PseudoRandom Number Generator in EDK II Network PackageTianoCore edk2 CVE-2023-45236Predictable TCP ISNs in EDK II Network PackageTianoCore edk2 CVE-2023-45231Out-of-Bounds Read in EDK II Network PackageTianoCore edk2 CVE-2023-45229Out-of-Bounds Read in EDK II Network PackageTianoCore edk2 CVE-2022-36764Heap Buffer Overflow in Tcg2MeasurePeImageTianoCore edk2 CVE-2022-36763Heap Buffer Overflow in Tcg2MeasureGptTableTianoCore edk2 30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.