Vulnerability index

Browse CVEs

250 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Epyc 8024pn Firmware MEDIUM 6.0
CVE-2023-20584

IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a c…

Mitigation only
Fix from $1,600 2024-08-13
Athlon Silver 3050u Firmware HIGH 8.2
CVE-2022-23815

Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to …

Mitigation only
Fix from $1,950 2024-08-13
Radeon Software MEDIUM 6.0
CVE-2023-20510

An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting i…

Fix: 23.12.1+
Fix from $1,600 2024-08-13
Epyc 7203 Firmware HIGH 8.2
CVE-2021-26344

An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the B…

Mitigation only
Fix from $1,950 2024-08-13
Radeon Software MEDIUM 6.0
CVE-2021-26367

A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for th…

Fix: 23.12.1+
Fix from $1,600 2024-08-13
Epyc 7203 Firmware HIGH 7.9
CVE-2024-21978

Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data…

Mitigation only
Fix from $1,950 2024-08-05
Epyc 7203 Firmware HIGH 7.9
CVE-2024-21980

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed res…

Mitigation only
Fix from $1,950 2024-08-05
Epyc 7203 Firmware MEDIUM 6.0
CVE-2023-31355

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing read…

Mitigation only
Fix from $1,600 2024-08-05
Ryzen 7 5700g Firmware MEDIUM 6.0
CVE-2023-20579

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potential…

Mitigation only
Fix from $1,600 2024-02-13
Epyc 7773x Firmware MEDIUM 6.0
CVE-2023-31346

Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

Mitigation only
Fix from $1,600 2024-02-13
Ryzen Embedded 5950e Firmware HIGH 7.8
CVE-2021-46757

Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual a…

Mitigation only
Fix from $1,950 2024-02-13
Radeon Software HIGH 7.5
CVE-2023-31320

Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of…

Fix: 23.q3 / 23.7.1+
Fix from $1,950 2023-11-14
Ryzen 7 5700g Firmware CRITICAL 9.8
CVE-2023-20596

Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbi…

Mitigation only
Fix from $2,300 2023-11-14
Epyc 7001 Firmware MEDIUM 6.5
CVE-2023-20592

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write…

No fix yet
Fix from $1,600 2023-11-14
Ryzen 3 5100 Firmware HIGH 8.1
CVE-2023-20571

A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resu…

Mitigation only
Fix from $1,950 2023-11-14
Ryzen 3 5100 Firmware HIGH 7.8
CVE-2023-20563

Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

No fix yet
Fix from $1,950 2023-11-14
Ryzen 3 5100 Firmware HIGH 7.8
CVE-2023-20565

Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

Mitigation only
Fix from $1,950 2023-11-14
Epyc 7232p Firmware HIGH 7.5
CVE-2023-20533

Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially…

Mitigation only
Fix from $1,950 2023-11-14
Epyc 7763 Firmware HIGH 7.5
CVE-2023-20566

Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.

Mitigation only
Fix from $1,950 2023-11-14
Epyc 7001 Firmware MEDIUM 5.7
CVE-2023-20521

TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially…

Mitigation only
Fix from $1,600 2023-11-14
Ryzen 9 3900 Firmware CRITICAL 9.8
CVE-2022-23820

Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

Mitigation only
Fix from $2,300 2023-11-14
Ryzen 9 3900 Firmware CRITICAL 9.8
CVE-2022-23821

Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.

Mitigation only
Fix from $2,300 2023-11-14
Epyc 7001 Firmware HIGH 7.5
CVE-2021-46774

Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially…

Mitigation only
Fix from $1,950 2023-11-14
Ryzen 7 5700g Firmware MEDIUM 6.1
CVE-2021-46758

Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyon…

Mitigation only
Fix from $1,600 2023-11-14
Epyc 9654p Firmware MEDIUM 5.5
CVE-2021-46766

Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to …

Mitigation only
Fix from $1,600 2023-11-14
Epyc 9654p Firmware MEDIUM 5.3
CVE-2022-23830

SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.

Mitigation only
Fix from $1,600 2023-11-14
Radeon Software HIGH 7.8
CVE-2023-20598

An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control…

Fix: 23.q4 / 23.9.2+
Fix from $1,950 2023-10-17
Ryzen 3 3100 Firmware MEDIUM 5.5
CVE-2023-20597

Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

Mitigation only
Fix from $1,600 2023-09-20
Ryzen Master MEDIUM 6.7
CVE-2023-20564

Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory read…

Fix: 2.11.2.2659+
Fix from $1,600 2023-08-15
Radeon Software CRITICAL 9.8
CVE-2023-20586

A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson R…

Mitigation only
Fix from $2,300 2023-08-08