
CVE-2017-5731 – edk2: Privilege escalation via processing of malformed files in TianoCompress.c
https://notcve.org/view.php?id=CVE-2017-5731
06 Aug 2019 — Bounds checking in Tianocompress before November 7, 2017 may allow an authenticated user to potentially enable an escalation of privilege via local access. La comprobación de límites en Tianocompress en versiones anteriores al 7 de noviembre de 2017 puede permitir que un usuario autenticado permita potencialmente una escalada de privilegios mediante el acceso local. It was discovered that EDK II was not properly performing bounds checks in Tianocompress, which could lead to a buffer overflow. An authenticat... • https://bugzilla.tianocore.org/show_bug.cgi?id=686 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-287: Improper Authentication •

CVE-2014-4859 – HP Security Bulletin HPSBHF03084
https://notcve.org/view.php?id=CVE-2014-4859
08 Aug 2014 — Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restrictions via crafted data. Un desbordamiento de enteros en la fase Drive Execution Environment (DXE) en la funcionalidad Capsule Update en la implementación de UEFI en EDK2, permite a atacantes físicamente próximos omitir las restricciones de acceso previstas por medio de datos diseñados. Potential security vulner... • http://www.kb.cert.org/vuls/id/552286 • CWE-190: Integer Overflow or Wraparound •

CVE-2014-4860 – HP Security Bulletin HPSBHF03084
https://notcve.org/view.php?id=CVE-2014-4860
08 Aug 2014 — Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase. Múltiples desbordamientos de enteros en la fase de arranque de Pre-EFI Initialization (PEI) en la funcionalidad Capsule Update en la implementación de UEFI en EDK2, permiten a atacantes físicamente próximos omitir... • http://www.kb.cert.org/vuls/id/552286 • CWE-190: Integer Overflow or Wraparound •