Vulnerabilities > Insyde > Insydeh2O > 05.51.45

DATE CVE VULNERABILITY TITLE RISK
2022-11-14 CVE-2022-34325 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Insyde Insydeh2O
DMA transactions which are targeted at input buffers used for the StorageSecurityCommandDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack.
local
high complexity
insyde CWE-367
7.8
2022-09-28 CVE-2022-36448 Improper Input Validation vulnerability in Insyde Insydeh2O
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
low complexity
insyde CWE-20
8.2
2022-09-23 CVE-2022-35893 Improper Input Validation vulnerability in Insyde Insydeh2O
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5.
local
low complexity
insyde CWE-20
8.2