EDK2是Tianocore社区的一套基于UEFI和PI规范的跨平台固件开发环境。 EDK2存在安全漏洞,该漏洞源于引导加载程序中加载无效固件时存在内存损坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Qualcomm, Inc. | Snapdragon | FastConnect 6200 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-47372 | 9.0 CRITICAL | Buffer Copy Without Checking Size of Input in Boot |
| CVE-2025-27063 | 7.8 HIGH | Use After Free in Video |
| CVE-2025-47320 | 7.8 HIGH | Out-of-bounds Write in Audio |
| CVE-2025-47321 | 7.8 HIGH | Buffer Copy Without Checking Size of Input in Core Services |
| CVE-2025-47322 | 7.8 HIGH | Use After Free in Automotive Linux OS |
| CVE-2025-47323 | 7.8 HIGH | Integer Overflow or Wraparound in Audio |
| CVE-2025-47350 | 7.8 HIGH | Use After Free in DSP Service |
| CVE-2025-47387 | 7.8 HIGH | Untrusted Pointer Dereference in Camera |
| CVE-2025-47319 | 6.7 MEDIUM | Exposure of Sensitive System Information to an Unauthorized Control Sphere in HLOS |
| CVE-2025-47325 | 6.5 MEDIUM | Untrusted Pointer Dereference in TZ Firmware |
No comments yet