Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 10.0
CVE-2023-20591
Improper re-initialization of IOMMU during the DRTM event
may permit an untrusted platform configuration to persist, allowing an attacker
to read or …
Epyc 8024pn Firmware
Mitigation only
MEDIUM 6.4
CVE-2023-20578
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 privileges and access to the
BIOS menu or UEFI shell to modify the commu…
Epyc 8024pn Firmware
Mitigation only
MEDIUM 6.0
CVE-2023-20584
IOMMU improperly handles certain special address
ranges with invalid device table entries (DTEs), which may allow an attacker
with privileges and a c…
Epyc 8024pn Firmware
Mitigation only
HIGH 8.2
CVE-2022-23815
Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to …
Athlon Silver 3050u Firmware
Mitigation only
HIGH 8.2
CVE-2021-26344
An out of bounds memory write when processing the AMD
PSP1 Configuration Block (APCB) could allow an attacker with access the ability
to modify the B…
Epyc 7203 Firmware
Mitigation only
HIGH 7.9
CVE-2024-21978
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data…
Epyc 7203 Firmware
Mitigation only
HIGH 7.9
CVE-2024-21980
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed res…
Epyc 7203 Firmware
Mitigation only
MEDIUM 6.0
CVE-2023-31355
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing read…
Epyc 7203 Firmware
Mitigation only
MEDIUM 6.0
CVE-2023-20579
Improper
Access Control in the AMD SPI protection feature may allow a user with Ring0
(kernel mode) privileged access to bypass protections potential…
Ryzen 7 5700g Firmware
Mitigation only
MEDIUM 6.0
CVE-2023-31346
Failure to initialize
memory in SEV Firmware may allow a privileged attacker to access stale data
from other guests.
Epyc 7773x Firmware
Mitigation only
HIGH 7.8
CVE-2021-46757
Insufficient checking of memory buffer in ASP
Secure OS may allow an attacker with a malicious TA to read/write to the ASP
Secure OS kernel virtual a…
Ryzen Embedded 5950e Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-20596
Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbi…
Ryzen 7 5700g Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-20592
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write…
Epyc 7001 Firmware
No fix yet
HIGH 8.1
CVE-2023-20571
A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resu…
Ryzen 3 5100 Firmware
Mitigation only
HIGH 7.8
CVE-2023-20563
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
Ryzen 3 5100 Firmware
No fix yet
HIGH 7.8
CVE-2023-20565
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
Ryzen 3 5100 Firmware
Mitigation only
HIGH 7.5
CVE-2023-20533
Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially…
Epyc 7232p Firmware
Mitigation only
HIGH 7.5
CVE-2023-20566
Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
Epyc 7763 Firmware
Mitigation only
MEDIUM 5.7
CVE-2023-20521
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially…
Epyc 7001 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-23820
Failure to validate the AMD SMM communication buffer
may allow an attacker to corrupt the SMRAM potentially leading to arbitrary
code execution.
Ryzen 9 3900 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-23821
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
Ryzen 9 3900 Firmware
Mitigation only
HIGH 7.5
CVE-2021-46774
Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially…
Epyc 7001 Firmware
Mitigation only
MEDIUM 6.1
CVE-2021-46758
Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyon…
Ryzen 7 5700g Firmware
Mitigation only
MEDIUM 5.5
CVE-2021-46766
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to …
Epyc 9654p Firmware
Mitigation only
MEDIUM 5.3
CVE-2022-23830
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
Epyc 9654p Firmware
Mitigation only
MEDIUM 5.5
CVE-2023-20597
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Ryzen 3 3100 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-20586
A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson R…
Radeon Software
Mitigation only
HIGH 7.8
CVE-2023-20555
Insufficient input validation in
CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting
an arbitrary bit in an attacker-cont…
Ryzen 3 3300 Firmware
Mitigation only
MEDIUM 6.8
CVE-2023-20589
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in …
Ryzen 5 Pro 3400g Firmware
Mitigation only
MEDIUM 6.5
CVE-2023-20575
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to m…
Epyc 7251 Firmware
Mitigation only