Radeon Software
by AMD
CVEs (52)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26393 | Med | 0.36 | 5.5 | 0.00 | Nov 9, 2022 | Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting… | ||
| CVE-2021-26361 | Med | 0.36 | 5.5 | 0.00 | May 12, 2022 | A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2 bootloader potentially leading to information disclosure. | ||
| CVE-2020-12960 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2021 | AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS). | ||
| CVE-2020-12905 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2021 | Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004403 may lead to arbitrary information disclosure. | ||
| CVE-2020-12901 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2021 | Arbitrary Free After Use in AMD Graphics Driver for Windows 10 may lead to KASLR bypass or information disclosure. | ||
| CVE-2020-12920 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2021 | A potential denial of service issue exists in the AMD Display driver Escape 0x130007 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck. | ||
| CVE-2020-12904 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2021 | Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004203 may lead to arbitrary information disclosure. | ||
| CVE-2020-12897 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2021 | Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass. | ||
| CVE-2020-12987 | Med | 0.36 | 5.5 | 0.00 | Jun 11, 2021 | A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead to KASLR bypass. | ||
| CVE-2023-20510 | Med | 0.31 | 4.7 | 0.00 | Aug 13, 2024 | An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service. | ||
| CVE-2021-26363 | Med | 0.29 | 4.4 | 0.00 | May 12, 2022 | A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure. | ||
| CVE-2023-31307 | Low | 0.15 | 2.3 | 0.00 | Aug 13, 2024 | Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service. |
- risk 0.36cvss 5.5epss 0.00
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting…
- risk 0.36cvss 5.5epss 0.00
A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2 bootloader potentially leading to information disclosure.
- risk 0.36cvss 5.5epss 0.00
AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS).
- risk 0.36cvss 5.5epss 0.00
Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004403 may lead to arbitrary information disclosure.
- risk 0.36cvss 5.5epss 0.00
Arbitrary Free After Use in AMD Graphics Driver for Windows 10 may lead to KASLR bypass or information disclosure.
- risk 0.36cvss 5.5epss 0.00
A potential denial of service issue exists in the AMD Display driver Escape 0x130007 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck.
- risk 0.36cvss 5.5epss 0.00
Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004203 may lead to arbitrary information disclosure.
- risk 0.36cvss 5.5epss 0.00
Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass.
- risk 0.36cvss 5.5epss 0.00
A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead to KASLR bypass.
- risk 0.31cvss 4.7epss 0.00
An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.
- risk 0.29cvss 4.4epss 0.00
A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.
- risk 0.15cvss 2.3epss 0.00
Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.
Page 3 of 3