Lucene search

K
cvelistCertccCVELIST:CVE-2014-4860
HistoryJan 31, 2020 - 3:08 p.m.

CVE-2014-4860

2020-01-3115:08:16
certcc
www.cve.org
2

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.2%

Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended access restrictions by providing crafted data that is not properly handled during the coalescing phase.

CNA Affected

[
  {
    "product": "SCT3",
    "vendor": "Phoenix Technologies Ltd.",
    "versions": [
      {
        "status": "affected",
        "version": "before 5/23/2014"
      }
    ]
  },
  {
    "product": "BIOS",
    "vendor": "American Megatrends Incorporated (AMI)",
    "versions": [
      {
        "status": "affected",
        "version": "unknown"
      }
    ]
  }
]

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.2%