VYPR

bootloader

by AMD

CVEs (3)

  • CVE-2021-46760CriMay 9, 2023
    risk 0.64cvss 9.8epss 0.01

    A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may potentially lead to an attacker leaking sensitive information or achieving code execution.

  • CVE-2021-26369HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

  • CVE-2021-26371MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.