Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2021-46760
A malicious or compromised UApp or ABL can send
a malformed system call to the bootloader, which may result in an out-of-bounds
memory access that ma…
Ryzen 3945wx Firmware
Mitigation only
CRITICAL 9.1
CVE-2021-46754
Insufficient input validation in the ASP (AMD
Secure Processor) bootloader may allow an attacker with a compromised Uapp or
ABL to coerce the bootloa…
Ryzen 5300g Firmware
Mitigation only
CRITICAL 9.1
CVE-2021-46756
Insufficient validation of inputs in
SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an
attacker with a malicious Uapp or A…
Epyc 72f3 Firmware
Mitigation only
HIGH 8.8
CVE-2021-46773
Insufficient input validation in ABL may enable
a privileged attacker to corrupt ASP memory, potentially resulting in a loss of
integrity or code exe…
Ryzen 6600h Firmware
No fix yet
HIGH 7.5
CVE-2021-46755
Failure to unmap certain SysHub mappings in
error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker
with a malicious bootloade…
Ryzen 5500 Firmware
Mitigation only
HIGH 7.5
CVE-2021-46765
Insufficient input validation in ASP may allow
an attacker with a compromised SMM to induce out-of-bounds memory reads within
the ASP, potentially le…
Ryzen 6600h Firmware
Mitigation only
HIGH 7.5
CVE-2021-46794
Insufficient bounds checking in ASP (AMD Secure
Processor) may allow for an out of bounds read in SMI (System Management
Interface) mailbox checksum …
Ryzen 5300g Firmware
Mitigation only
MEDIUM 6.1
CVE-2021-46759
Improper syscall input validation in AMD TEE
(Trusted Execution Environment) may allow an attacker with physical access and
control of a Uapp that ru…
Ryzen 5300g Firmware
Mitigation only
MEDIUM 5.9
CVE-2021-46792
Time-of-check Time-of-use (TOCTOU) in the
BIOS2PSP command may allow an attacker with a malicious BIOS to create a race
condition causing the ASP boo…
Ryzen 5300g Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-20520
Improper access control settings in ASP
Bootloader may allow an attacker to corrupt the return address causing a
stack-based buffer overrun potential…
Epyc 72f3 Firmware
Mitigation only
CRITICAL 9.1
CVE-2021-46753
Failure to validate the length fields of the ASP
(AMD Secure Processor) sensor fusion hub headers may allow an attacker with a
malicious Uapp or ABL …
Ryzen 6600h Firmware
No fix yet
CRITICAL 9.1
CVE-2021-46762
Insufficient input validation in the SMU may
allow an attacker to corrupt SMU SRAM potentially leading to a loss of
integrity or denial of service.
Epyc 72f3 Firmware
Mitigation only
HIGH 8.8
CVE-2021-46769
Insufficient syscall input validation in the ASP
Bootloader may allow a privileged attacker to execute arbitrary DMA copies,
which can lead to code e…
Epyc 72f3 Firmware
Mitigation only
HIGH 7.5
CVE-2021-46763
Insufficient input validation in the SMU may
enable a privileged attacker to write beyond the intended bounds of a shared
memory buffer potentially l…
Epyc 72f3 Firmware
Mitigation only
HIGH 7.5
CVE-2021-46764
Improper validation of DRAM addresses in SMU may
allow an attacker to overwrite sensitive memory locations within the ASP
potentially resulting in a …
Epyc 72f3 Firmware
Mitigation only
HIGH 7.5
CVE-2022-23818
Insufficient input validation on the model
specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest
memory integrity.
Epyc 72f3 Firmware
Mitigation only
HIGH 7.5
CVE-2023-20524
An attacker with a compromised ASP could
possibly send malformed commands to an ASP on another CPU, resulting in an out
of bounds write, potentially …
Epyc 72f3 Firmware
Mitigation only
MEDIUM 6.8
CVE-2021-46775
Improper input validation in ABL may enable an
attacker with physical access, to perform arbitrary memory overwrites,
potentially leading to a loss o…
Epyc 72f3 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-26379
Insufficient input validation of mailbox data in the
SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially
leading to a loss of i…
Epyc 72f3 Firmware
Mitigation only
HIGH 8.2
CVE-2021-26365
Certain size values in firmware binary headers
could trigger out of bounds reads during signature validation, leading to
denial of service or potenti…
Ryzen 5 2400g Firmware
Mitigation only
HIGH 7.5
CVE-2021-26406
Insufficient validation in parsing Owner's
Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization)
and SEV-ES user appl…
Epyc 7232p Firmware
Mitigation only
HIGH 7.5
CVE-2021-46749
Insufficient bounds checking in ASP (AMD Secure
Processor) may allow for an out of bounds read in SMI (System Management
Interface) mailbox checksum …
Ryzen 5300g Firmware
Mitigation only
HIGH 7.4
CVE-2021-26356
A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to memory potentially resulting
in S3 data corruption…
Epyc 7001 Firmware
Mitigation only
HIGH 7.1
CVE-2021-26397
Insufficient address validation, may allow an
attacker with a compromised ABL and UApp to corrupt sensitive memory locations
potentially resulting in…
Epyc 72f3 Firmware
No fix yet
MEDIUM 5.5
CVE-2021-26354
Insufficient bounds checking in ASP may allow an
attacker to issue a system call from a compromised ABL which may cause
arbitrary memory values to be…
Epyc 7773x Firmware
Mitigation only
MEDIUM 5.5
CVE-2021-26371
A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may result in exposure of
ASP memory to userspace, po…
Epyc 7773x Firmware
Mitigation only
HIGH 8.8
CVE-2023-20558
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalat…
Ryzen 7 5700g Firmware
Mitigation only
HIGH 8.8
CVE-2023-20559
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escal…
Ryzen 7 5700g Firmware
Mitigation only
HIGH 7.5
CVE-2023-20531
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a de…
Epyc 7h12 Firmware
Mitigation only
MEDIUM 5.3
CVE-2023-20532
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
Epyc 7h12 Firmware
Mitigation only