VYPR

Vendor CVEs

AMD

All CVEs

517 total · sorted by risk
  • CVE-2024-21945HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-21939HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2024-21938HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-21937HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

  • CVE-2023-31349HigAug 13, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2023-31348HigAug 13, 2024
    risk 0.47cvss 7.3epss 0.00

    A DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2023-31341HigAug 13, 2024
    risk 0.47cvss 7.3epss 0.00

    Insufficient validation of the Input Output Control (IOCTL) input buffer in AMD μProf may allow an authenticated attacker to cause an out-of-bounds write, potentially causing a Windows® OS crash, resulting in denial of service.

  • CVE-2022-23817HigAug 13, 2024
    risk 0.47cvss epss 0.00

    Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the ASP Secure OS kernel virtual address space, potentially resulting in privilege escalation.

  • CVE-2021-26344HigAug 13, 2024
    risk 0.47cvss 7.2epss 0.00

    An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.

  • CVE-2021-26311HigMay 13, 2021
    risk 0.47cvss 7.2epss 0.02

    In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a malicious administrator has…

  • CVE-2020-12967HigMay 13, 2021
    risk 0.47cvss 7.2epss 0.02

    The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.

  • CVE-2025-54512HigAug 11, 2026
    risk 0.46cvss epss 0.00

    A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to escalate privileges, potentially resulting in arbitrary code execution.

  • CVE-2025-8087HigAug 11, 2026
    risk 0.46cvss epss 0.00

    A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution.

  • CVE-2021-46747HigJun 1, 2026
    risk 0.46cvss epss 0.00

    Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures leading to a potential escalation of privileges.

  • CVE-2026-49121HigJun 1, 2026
    risk 0.46cvss 8.1epss 0.01

    AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle…

  • CVE-2025-54518HigMay 15, 2026
    risk 0.46cvss 7.0epss 0.00

    Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

  • CVE-2024-36334HigMay 15, 2026
    risk 0.46cvss epss 0.00

    Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory to be run with elevated privileges potentially leading to arbitrary code execution.

  • CVE-2025-29938HigMay 15, 2026
    risk 0.46cvss epss 0.00

    An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to write to an arbitrary memory address resulting in denial of service or arbitrary code execution.

  • CVE-2023-31316HigMay 15, 2026
    risk 0.46cvss epss 0.00

    Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure Processor (ASP) could allow an attacker with the ability to write outside the trusted memory range (TMR) to change the execution flow of the Video Core Next…

  • CVE-2025-48512HigMay 15, 2026
    risk 0.46cvss epss 0.00

    Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.

  • CVE-2025-62628HigMay 14, 2026
    risk 0.46cvss epss 0.00

    Unsafe OpenSSL initialization within some AMD optional tools may allow a local user-privileged attacker to inject a malicious DLL, potentially resulting in arbitrary code execution.

  • CVE-2025-61969HigFeb 11, 2026
    risk 0.46cvss epss 0.00

    Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.

  • CVE-2024-36320HigFeb 11, 2026
    risk 0.46cvss epss 0.00

    Integer Overflow within atihdwt6.sys can allow a local attacker to cause out of bound read/write potentially leading to loss of confidentiality, integrity and availability

  • CVE-2025-29950HigFeb 10, 2026
    risk 0.46cvss epss 0.00

    Improper input validation in system management mode (SMM) could allow a privileged attacker to overwrite stack memory leading to arbitrary code execution.

  • CVE-2024-36355HigFeb 10, 2026
    risk 0.46cvss epss 0.00

    Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify execution flow for S3 (sleep) wake up, potentially resulting in arbitrary code execution.

  • CVE-2021-26381HigFeb 10, 2026
    risk 0.46cvss epss 0.00

    Improper system call parameter validation in the Trusted OS may allow a malicious driver to perform mapping or unmapping operations on a large number of pages, potentially resulting in kernel memory corruption.

  • CVE-2025-48510HigNov 24, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability.

  • CVE-2024-25743HigMay 15, 2024
    risk 0.46cvss 7.1epss 0.00

    In the Linux kernel through 6.9, an untrusted hypervisor can inject virtual interrupts 0 and 14 at any point in time and can trigger the SIGFPE signal handler in userspace applications. This affects AMD SEV-SNP and AMD SEV-ES.

  • CVE-2023-20587HigFeb 13, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.

  • CVE-2021-26397HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.00

    Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability.

  • CVE-2021-46779HigJan 11, 2023
    risk 0.46cvss 7.1epss 0.00

    Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential loss of integrity and availability.

  • CVE-2021-26402HigJan 11, 2023
    risk 0.46cvss 7.1epss 0.00

    Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regions which may lead to a potential loss of integrity and availability.

  • CVE-2021-26366HigMay 12, 2022
    risk 0.46cvss 7.1epss 0.00

    An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.

  • CVE-2021-26362HigMay 12, 2022
    risk 0.46cvss 7.1epss 0.00

    A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive System Management Network (SMN) registers leading to a loss of integrity and availability.

  • CVE-2021-26408HigMay 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.

  • CVE-2021-26370HigMay 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.

  • CVE-2021-26332HigMay 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.

  • CVE-2020-12951HigNov 16, 2021
    risk 0.46cvss 7.0epss 0.00

    Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations.

  • CVE-2020-12946HigNov 16, 2021
    risk 0.46cvss 7.1epss 0.00

    Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service.

  • CVE-2020-12894HigNov 15, 2021
    risk 0.46cvss 7.1epss 0.00

    Arbitrary Write in AMD Graphics Driver for Windows 10 in Escape 0x40010d may lead to arbitrary write to kernel memory or denial of service.

  • CVE-2020-12899HigNov 15, 2021
    risk 0.46cvss 7.1epss 0.00

    Arbitrary Read in AMD Graphics Driver for Windows 10 may lead to KASLR bypass or denial of service.

  • CVE-2025-48516MedMay 15, 2026
    risk 0.45cvss epss 0.00

    Insecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege to abuse the unprotected PMIC interface to create a permanent denial of service condition or affect the integrity of the memory module.

  • CVE-2025-48513MedMay 15, 2026
    risk 0.45cvss epss 0.00

    Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of confidentiality or availability.

  • CVE-2025-48521MedMay 15, 2026
    risk 0.45cvss epss 0.00

    Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in a loss of platform integrity or crash.

  • CVE-2025-48520MedMay 15, 2026
    risk 0.45cvss epss 0.00

    An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure or a crash

  • CVE-2025-0045MedMay 15, 2026
    risk 0.45cvss epss 0.00

    Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service

  • CVE-2025-48518MedFeb 11, 2026
    risk 0.45cvss epss 0.00

    Improper input validation in AMD Graphics Driver could allow a local attacker to write out of bounds, potentially resulting in loss of integrity or denial of service.

  • CVE-2025-29939MedFeb 10, 2026
    risk 0.45cvss epss 0.00

    Improper access control in secure encrypted virtualization (SEV) could allow a privileged attacker to write to the reverse map page (RMP) during secure nested paging (SNP) initialization, potentially resulting in a loss of guest memory confidentiality and integrity.

  • CVE-2025-29944MedMay 15, 2026
    risk 0.44cvss epss 0.00

    A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash

  • CVE-2024-36332MedMay 15, 2026
    risk 0.44cvss epss 0.00

    Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to perform unauthorized access to specific victim range of GPU MMIO register space, potentially causing the host OS to reboot and creating a Denial of Service…

Page 5 of 11