Insyde / Kernel
33 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-52880 | An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel… | HIGH | 7.9 | May 15, 2025 |
| CVE-2024-49200 | An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has… | MEDIUM | 6.4 | Apr 15, 2025 |
| CVE-2024-25078 | A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.0… | HIGH | 7.4 | May 15, 2024 |
| CVE-2023-47252 | An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, le… | MEDIUM | 6.3 | Apr 26, 2024 |
| CVE-2022-46897 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The CapsuleIFWUSmm driver does not check the return value from a method or function. T… | MEDIUM | 5.3 | Apr 22, 2024 |
| CVE-2023-28468 | An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler t… | MEDIUM | 6.5 | Aug 3, 2023 |
| CVE-2022-36337 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitra… | HIGH | 8.2 | Nov 23, 2022 |
| CVE-2022-35407 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver o… | HIGH | 7.8 | Nov 22, 2022 |
| CVE-2022-35897 | An stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. If the attacker… | MEDIUM | 6.8 | Nov 21, 2022 |
| CVE-2022-30772 | Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSmm driver i… | HIGH | 8.2 | Nov 15, 2022 |
| CVE-2022-30771 | Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead to SMRAM… | HIGH | 8.2 | Nov 15, 2022 |
| CVE-2022-30283 | In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that cou… | HIGH | 7.5 | Nov 15, 2022 |
| CVE-2022-29279 | Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted pointer allows tampering with SMRAM and… | HIGH | 8.2 | Nov 15, 2022 |
| CVE-2022-29278 | Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer checks within the NvmExpressDxe driver… | HIGH | 8.2 | Nov 15, 2022 |
| CVE-2022-29276 | SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRA… | HIGH | 8.2 | Nov 15, 2022 |
| CVE-2022-29275 | In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation… | HIGH | 8.2 | Nov 15, 2022 |
| CVE-2022-33986 | DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. DMA attacks on the parameter buffer used… | MEDIUM | 6.4 | Nov 14, 2022 |
| CVE-2022-33985 | DMA transactions which are targeted at input buffers used for the NvmExpressDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA… | HIGH | 7.0 | Nov 14, 2022 |
| CVE-2022-33984 | DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA tr… | HIGH | 7.0 | Nov 14, 2022 |
| CVE-2022-33983 | DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRAM corruption through a TOCTOU attack. D… | HIGH | 7.0 | Nov 14, 2022 |
| CVE-2022-33982 | DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on the SMI handler and lead to corruption of… | MEDIUM | 6.4 | Nov 14, 2022 |
| CVE-2022-33909 | DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA tr… | HIGH | 7.0 | Nov 14, 2022 |
| CVE-2022-33908 | DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA t… | HIGH | 7.0 | Nov 14, 2022 |
| CVE-2022-33907 | DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver could cause SMRAM corruption through a TOCT… | MEDIUM | 6.4 | Nov 14, 2022 |
| CVE-2022-33906 | DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMRAM corruption through a TOCTOU attack.… | MEDIUM | 6.4 | Nov 14, 2022 |
Showing 1 to 25 of 33 CVEs