Known vulnerabilities in NvmExpressDxe
Vendor:
Insyde Software
Software:
NvmExpressDxe
Software CPE:
cpe:2.3:h:insyde_software:nvmexpressdxe:*:*:*:*:*:*:*:*
Website:
https://www.insyde.com/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU60284 - Memory corruption CVE-2022-24031 |
CWE-119 | High | 5.1: 05.16.42, 5.2: 05.26.42, 5.3: 05.35.42, 5.4: 05.43.42, 5.5: 05.51.42 | 03.02.2022 |
SB2022020320 |
||
| #VU60275 - Untrusted Pointer Dereference CVE-2021-41838 |
CWE-822 | High | 5.1: 05.16.42, 5.2: 05.26.42, 5.3: 05.35.42, 5.4: 05.43.42, 5.5: 05.51.42 | 03.02.2022 |
SB2022020315 |
||
| #VU60265 - Insecure Default Variable Initialization CVE-2021-41839 |
CWE-453 | High | 5.1: 05.16.25, 5.2: 05.26.25, 5.3: 05.35.25, 5.4: 05.43.25, 5.5: 05.51.25 | 03.02.2022 |
SB2022020306 |