Vendor CVEs
AMD
All CVEs
517 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-12930 | Hig | 0.51 | 7.8 | 0.00 | Nov 9, 2022 | Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. | ||
| CVE-2021-26384 | Hig | 0.51 | 7.8 | 0.00 | Jul 14, 2022 | A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when triggering an SMI resulting in a potential loss of resources. | ||
| CVE-2021-26386 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2022 | A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code execution. | ||
| CVE-2021-26317 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2022 | Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution. | ||
| CVE-2021-26369 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2022 | A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses. | ||
| CVE-2021-46771 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application. | ||
| CVE-2021-26353 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity. | ||
| CVE-2021-26324 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs. | ||
| CVE-2020-12891 | Hig | 0.51 | 7.8 | 0.00 | Feb 4, 2022 | AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable. | ||
| CVE-2021-26335 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values prior to signature validation potentially resulting in arbitrary code execution. | ||
| CVE-2021-26331 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution. | ||
| CVE-2021-26323 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity. | ||
| CVE-2021-26315 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used. | ||
| CVE-2020-12961 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI ROM protections. | ||
| CVE-2020-12944 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution. | ||
| CVE-2021-26326 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity. | ||
| CVE-2020-12962 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Escape call interface in the AMD Graphics Driver for Windows may cause privilege escalation. | ||
| CVE-2020-12903 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Out of Bounds Write and Read in AMD Graphics Driver for Windows 10 in Escape 0x6002d03 may lead to escalation of privilege or denial of service. | ||
| CVE-2020-12893 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Stack Buffer Overflow in AMD Graphics Driver for Windows 10 in Escape 0x15002a may lead to escalation of privilege or denial of service. | ||
| CVE-2020-12898 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Stack Buffer Overflow in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | ||
| CVE-2020-12892 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution. | ||
| CVE-2020-12963 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the system. | ||
| CVE-2020-12929 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to bypass security restrictions and achieve arbitrary code execution . | ||
| CVE-2020-12902 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Arbitrary Decrement Privilege Escalation in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | ||
| CVE-2020-12900 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | An arbitrary write vulnerability in the AMD Radeon Graphics Driver for Windows 10 potentially allows unprivileged users to gain Escalation of Privileges and cause Denial of Service. | ||
| CVE-2020-12895 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | Pool/Heap Overflow in AMD Graphics Driver for Windows 10 in Escape 0x110037 may lead to escalation of privilege, information disclosure or denial of service. | ||
| CVE-2020-12964 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2021 | A potential privilege escalation/denial of service issue exists in the AMD Radeon Kernel Mode driver Escape 0x2000c00 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck or write to leak information. | ||
| CVE-2020-12986 | Hig | 0.51 | 7.8 | 0.00 | Jun 11, 2021 | An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code execution in the kernel, leading to escalation of privilege or denial of service. | ||
| CVE-2020-12985 | Hig | 0.51 | 7.8 | 0.00 | Jun 11, 2021 | An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | ||
| CVE-2020-12983 | Hig | 0.51 | 7.8 | 0.00 | Jun 11, 2021 | An out of bounds write vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privileges or denial of service. | ||
| CVE-2020-12982 | Hig | 0.51 | 7.8 | 0.00 | Jun 11, 2021 | An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | ||
| CVE-2020-12981 | Hig | 0.51 | 7.8 | 0.00 | Jun 11, 2021 | An insufficient input validation in the AMD Graphics Driver for Windows 10 may allow unprivileged users to unload the driver, potentially causing memory corruptions in high privileged processes, which can lead to escalation of privileges or denial of service. | ||
| CVE-2020-12980 | Hig | 0.51 | 7.8 | 0.00 | Jun 11, 2021 | An out of bounds write and read vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | ||
| CVE-2020-12927 | Hig | 0.51 | 7.8 | 0.00 | Nov 12, 2020 | A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated user to escalate privileges to NT authority system. | ||
| CVE-2020-12928 | Hig | 0.51 | 7.8 | 0.01 | Oct 13, 2020 | A vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT authority system. | ||
| CVE-2020-8950 | Hig | 0.51 | 7.8 | 0.01 | Feb 12, 2020 | The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that points to an arbitrary… | ||
| CVE-2015-7724 | Hig | 0.51 | 7.8 | 0.01 | Jun 7, 2017 | AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723. | ||
| CVE-2015-7723 | Hig | 0.51 | 7.8 | 0.01 | Jun 7, 2017 | AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack. | ||
| CVE-2025-54502 | Hig | 0.49 | 7.5 | 0.00 | Apr 16, 2026 | Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution. | ||
| CVE-2024-36354 | Hig | 0.49 | 7.5 | 0.00 | Sep 6, 2025 | Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in… | ||
| CVE-2024-21947 | Hig | 0.49 | 7.5 | 0.00 | Sep 6, 2025 | Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially resulting in arbitrary code execution at the SMM level. | ||
| CVE-2023-31345 | Hig | 0.49 | 7.5 | 0.00 | Feb 12, 2025 | Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution. | ||
| CVE-2023-31343 | Hig | 0.49 | 7.5 | 0.00 | Feb 11, 2025 | Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution. | ||
| CVE-2023-31342 | Hig | 0.49 | 7.5 | 0.00 | Feb 11, 2025 | Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution. | ||
| CVE-2023-20578 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2024 | A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution. | ||
| CVE-2022-23815 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2024 | Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution. | ||
| CVE-2023-31315 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2024 | Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution. | ||
| CVE-2023-31320 | Hig | 0.49 | 7.5 | 0.01 | Nov 14, 2023 | Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service. | ||
| CVE-2022-23820 | Hig | 0.49 | 7.5 | 0.01 | Nov 14, 2023 | Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution. | ||
| CVE-2021-46794 | Hig | 0.49 | 7.5 | 0.01 | May 9, 2023 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service. |
- risk 0.51cvss 7.8epss 0.00
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
- risk 0.51cvss 7.8epss 0.00
A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when triggering an SMI resulting in a potential loss of resources.
- risk 0.51cvss 7.8epss 0.00
A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code execution.
- risk 0.51cvss 7.8epss 0.00
Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.
- risk 0.51cvss 7.8epss 0.00
Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.
- risk 0.51cvss 7.8epss 0.00
Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.
- risk 0.51cvss 7.8epss 0.00
A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.
- risk 0.51cvss 7.8epss 0.00
AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.
- risk 0.51cvss 7.8epss 0.00
Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values prior to signature validation potentially resulting in arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.
- risk 0.51cvss 7.8epss 0.00
When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used.
- risk 0.51cvss 7.8epss 0.00
A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI ROM protections.
- risk 0.51cvss 7.8epss 0.00
Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.
- risk 0.51cvss 7.8epss 0.00
Escape call interface in the AMD Graphics Driver for Windows may cause privilege escalation.
- risk 0.51cvss 7.8epss 0.00
Out of Bounds Write and Read in AMD Graphics Driver for Windows 10 in Escape 0x6002d03 may lead to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
Stack Buffer Overflow in AMD Graphics Driver for Windows 10 in Escape 0x15002a may lead to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
Stack Buffer Overflow in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution.
- risk 0.51cvss 7.8epss 0.00
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the system.
- risk 0.51cvss 7.8epss 0.00
Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to bypass security restrictions and achieve arbitrary code execution .
- risk 0.51cvss 7.8epss 0.00
Arbitrary Decrement Privilege Escalation in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
An arbitrary write vulnerability in the AMD Radeon Graphics Driver for Windows 10 potentially allows unprivileged users to gain Escalation of Privileges and cause Denial of Service.
- risk 0.51cvss 7.8epss 0.00
Pool/Heap Overflow in AMD Graphics Driver for Windows 10 in Escape 0x110037 may lead to escalation of privilege, information disclosure or denial of service.
- risk 0.51cvss 7.8epss 0.00
A potential privilege escalation/denial of service issue exists in the AMD Radeon Kernel Mode driver Escape 0x2000c00 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck or write to leak information.
- risk 0.51cvss 7.8epss 0.00
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code execution in the kernel, leading to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
An out of bounds write vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privileges or denial of service.
- risk 0.51cvss 7.8epss 0.00
An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
An insufficient input validation in the AMD Graphics Driver for Windows 10 may allow unprivileged users to unload the driver, potentially causing memory corruptions in high privileged processes, which can lead to escalation of privileges or denial of service.
- risk 0.51cvss 7.8epss 0.00
An out of bounds write and read vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
- risk 0.51cvss 7.8epss 0.00
A potential vulnerability in a dynamically loaded AMD driver in AMD VBIOS Flash Tool SDK may allow any authenticated user to escalate privileges to NT authority system.
- risk 0.51cvss 7.8epss 0.01
A vulnerability in a dynamically loaded AMD driver in AMD Ryzen Master V15 may allow any authenticated user to escalate privileges to NT authority system.
- risk 0.51cvss 7.8epss 0.01
The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that points to an arbitrary…
- risk 0.51cvss 7.8epss 0.01
AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.
- risk 0.51cvss 7.8epss 0.01
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
- risk 0.49cvss 7.5epss 0.00
Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulting in arbitrary code execution.
- risk 0.49cvss 7.5epss 0.00
Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in…
- risk 0.49cvss 7.5epss 0.00
Improper input validation in the system management mode (SMM) could allow a privileged attacker to overwrite arbitrary memory potentially resulting in arbitrary code execution at the SMM level.
- risk 0.49cvss 7.5epss 0.00
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
- risk 0.49cvss 7.5epss 0.00
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
- risk 0.49cvss 7.5epss 0.00
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
- risk 0.49cvss 7.5epss 0.00
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.
- risk 0.49cvss 7.5epss 0.00
Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.
- risk 0.49cvss 7.5epss 0.01
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
- risk 0.49cvss 7.5epss 0.01
Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.
- risk 0.49cvss 7.5epss 0.01
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
- risk 0.49cvss 7.5epss 0.01
Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.
Page 3 of 11