VYPR

Vendor CVEs

AMD

All CVEs

517 total · sorted by risk
  • CVE-2021-46765HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service.

  • CVE-2021-46755HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.

  • CVE-2023-20524HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.00

    An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.

  • CVE-2022-23818HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.

  • CVE-2021-46764HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.

  • CVE-2021-46763HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity.

  • CVE-2021-46749HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.

  • CVE-2021-26406HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service.

  • CVE-2023-20531HigJan 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.

  • CVE-2023-20530HigJan 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.

  • CVE-2023-20529HigJan 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.

  • CVE-2023-20522HigJan 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service.

  • CVE-2022-27674HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.

  • CVE-2022-27673HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Insufficient access controls in the AMD Link Android app may potentially result in information disclosure.

  • CVE-2022-23831HigNov 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service.

  • CVE-2020-12965HigFeb 4, 2022
    risk 0.49cvss 7.5epss 0.02

    When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.

  • CVE-2021-26338HigNov 16, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.

  • CVE-2021-26322HigNov 16, 2021
    risk 0.49cvss 7.5epss 0.01

    Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.

  • CVE-2020-12988HigJun 11, 2021
    risk 0.49cvss 7.5epss 0.01

    A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.

  • CVE-2017-5927HigFeb 27, 2017
    risk 0.49cvss 7.5epss 0.02

    Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking…

  • CVE-2017-5926HigFeb 27, 2017
    risk 0.49cvss 7.5epss 0.02

    Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking…

  • CVE-2017-5925HigFeb 27, 2017
    risk 0.49cvss 7.5epss 0.02

    Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript,…

  • CVE-2021-26356HigMay 9, 2023
    risk 0.48cvss 7.4epss 0.00

    A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.

  • CVE-2025-54519HigFeb 12, 2026
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in Doc Nav could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2023-31313HigFeb 12, 2026
    risk 0.47cvss 7.2epss 0.00

    An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.

  • CVE-2025-52541HigFeb 11, 2026
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in Vivado could allow a local attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2025-29951HigFeb 10, 2026
    risk 0.47cvss epss 0.00

    A buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially resulting in privilege escalation and arbitrary code execution.

  • CVE-2025-0003HigNov 24, 2025
    risk 0.47cvss 7.3epss 0.00

    Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition potentially resulting in loss of confidentiality or availability

  • CVE-2025-52539HigNov 24, 2025
    risk 0.47cvss 7.3epss 0.00

    A buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced extensible interface (AXI), potentially resulting in loss of confidentiality, integrity, and/or availability.

  • CVE-2025-0005HigNov 24, 2025
    risk 0.47cvss 7.3epss 0.00

    Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, potentially resulting in crash or denial of service.

  • CVE-2024-21923HigNov 23, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-21922HigNov 23, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2025-62626HigNov 21, 2025
    risk 0.47cvss epss 0.00

    Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.

  • CVE-2025-0032HigSep 6, 2025
    risk 0.47cvss 7.2epss 0.00

    Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load malicious CPU microcode, potentially resulting in loss of integrity of x86 instruction execution.

  • CVE-2023-31325HigSep 6, 2025
    risk 0.47cvss 7.2epss 0.00

    Improper isolation of shared resources on System-on-a-chip (SOC) could a privileged attacker to tamper with the contents of the PSP reserved DRAM region potentially resulting in loss of confidentiality and integrity.

  • CVE-2023-31359HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2023-31358HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2025-0035HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Unquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.

  • CVE-2024-36339HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-36321HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Unquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrary code execution.

  • CVE-2024-21960HigMay 13, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Optimizing CPU Libraries (AOCL) installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2025-0014HigApr 2, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-36328HigApr 2, 2025
    risk 0.47cvss 7.3epss 0.00

    Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of integrity or availability.

  • CVE-2024-21966HigFeb 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2023-31361HigFeb 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in AMD Integrated Management Technology (AIM-T) Manageability Service could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2023-31360HigFeb 11, 2025
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-56161HigFeb 3, 2025
    risk 0.47cvss 7.2epss 0.01

    Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP.

  • CVE-2024-21958HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-21957HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-21946HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

Page 4 of 11