VYPR

Radeon Software

by AMD

CVEs (52)

  • CVE-2021-26393MedNov 9, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting…

  • CVE-2021-26361MedMay 12, 2022
    risk 0.36cvss 5.5epss 0.00

    A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2 bootloader potentially leading to information disclosure.

  • CVE-2020-12960MedNov 15, 2021
    risk 0.36cvss 5.5epss 0.00

    AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS).

  • CVE-2020-12905MedNov 15, 2021
    risk 0.36cvss 5.5epss 0.00

    Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004403 may lead to arbitrary information disclosure.

  • CVE-2020-12901MedNov 15, 2021
    risk 0.36cvss 5.5epss 0.00

    Arbitrary Free After Use in AMD Graphics Driver for Windows 10 may lead to KASLR bypass or information disclosure.

  • CVE-2020-12920MedNov 15, 2021
    risk 0.36cvss 5.5epss 0.00

    A potential denial of service issue exists in the AMD Display driver Escape 0x130007 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck.

  • CVE-2020-12904MedNov 15, 2021
    risk 0.36cvss 5.5epss 0.00

    Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004203 may lead to arbitrary information disclosure.

  • CVE-2020-12897MedNov 15, 2021
    risk 0.36cvss 5.5epss 0.00

    Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass.

  • CVE-2020-12987MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead to KASLR bypass.

  • CVE-2023-20510MedAug 13, 2024
    risk 0.31cvss 4.7epss 0.00

    An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.

  • CVE-2021-26363MedMay 12, 2022
    risk 0.29cvss 4.4epss 0.00

    A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.

  • CVE-2023-31307LowAug 13, 2024
    risk 0.15cvss 2.3epss 0.00

    Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.

Page 3 of 3