VYPR

Vendor CVEs

AMD

All CVEs

517 total · sorted by risk
  • CVE-2023-31309MedMay 15, 2026
    risk 0.44cvss epss 0.00

    Improper validation in Power Management Firmware (PMFW) may allow an attacker with privileges to pass malformed workload arguments when exporting table data from SMU to DRAM potentially resulting in a loss of confidentiality and/or availability.

  • CVE-2025-52536MedFeb 10, 2026
    risk 0.44cvss epss 0.00

    Improper Prevention of Lock Bit Modification in SEV firmware could allow a privileged attacker to downgrade firmware potentially resulting in a loss of integrity.

  • CVE-2025-0012MedFeb 10, 2026
    risk 0.44cvss epss 0.00

    Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged attacker corrupt or partially infer SMM memory resulting in loss of integrity or confidentiality.

  • CVE-2023-20568MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

  • CVE-2023-20567MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.00

    Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.

  • CVE-2021-46774MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.01

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

  • CVE-2023-20564MedAug 15, 2023
    risk 0.44cvss 6.7epss 0.00

    Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution.

  • CVE-2023-20589MedAug 8, 2023
    risk 0.44cvss 6.8epss 0.01

    An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. 

  • CVE-2021-46775MedMay 9, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution.

  • CVE-2022-23822MedApr 27, 2022
    risk 0.44cvss 6.8epss 0.00

    In this physical attack, an attacker may potentially exploit the Zynq-7000 SoC First Stage Boot Loader (FSBL) by bypassing authentication and loading a malicious image onto the device. This in turn may further allow the attacker to perform additional attacks such as such as…

  • CVE-2021-44850MedFeb 10, 2022
    risk 0.44cvss 6.8epss 0.00

    On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the ROM. Because the Zynq-7000's boot image header is unencrypted and unauthenticated before use, an attacker can modify the boot header stored on an SD card so that…

  • CVE-2020-12890MedDec 10, 2021
    risk 0.44cvss 6.7epss 0.00

    Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by…

  • CVE-2021-28695MedAug 27, 2021
    risk 0.44cvss 6.8epss 0.00

    IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically…

  • CVE-2021-27208MedMar 15, 2021
    risk 0.44cvss 6.8epss 0.00

    When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when reading in any parameters in the nand’s parameter page. IF a field read in from the parameter page is too large, this causes a buffer overflow that could…

  • CVE-2019-7246MedMay 18, 2020
    risk 0.44cvss 6.7epss 0.00

    An issue was discovered in atillk64.sys in AMD ATI Diagnostics Hardware Abstraction Sys/Overclocking Utility 5.11.9.0. The vulnerable driver exposes a wrmsr instruction and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to…

  • CVE-2025-0038MedOct 6, 2025
    risk 0.43cvss 6.6epss 0.00

    In AMD Zynq UltraScale+ devices, the lack of address validation when executing CSU runtime services through the PMU Firmware can allow access to isolated or protected memory spaces resulting in the loss of integrity and confidentiality.

  • CVE-2025-0037MedJun 10, 2025
    risk 0.43cvss 6.6epss 0.00

    In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated or protected memory spaces, resulting in the loss of integrity and confidentiality.

  • CVE-2024-36340MedMay 13, 2025
    risk 0.43cvss 6.6epss 0.00

    A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.

  • CVE-2022-29900MedJul 12, 2022
    risk 0.43cvss 6.5epss 0.04

    Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

  • CVE-2024-36347MedJun 27, 2025
    risk 0.42cvss 6.4epss 0.00

    Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in…

  • CVE-2024-36353MedMar 2, 2025
    risk 0.42cvss 6.5epss 0.00

    Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over memory values potentially leading to loss of confidentiality.

  • CVE-2023-20591MedAug 13, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.

  • CVE-2023-4969MedJan 16, 2024
    risk 0.42cvss 6.5epss 0.01

    A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

  • CVE-2023-20592MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

  • CVE-2023-20575MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.

  • CVE-2023-20527MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.

  • CVE-2023-20525MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.

  • CVE-2021-26403MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.00

    Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality.

  • CVE-2022-23825MedJul 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

  • CVE-2022-23823MedJun 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.

  • CVE-2021-46744MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.00

    An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.

  • CVE-2021-26341MedMar 11, 2022
    risk 0.42cvss 6.5epss 0.00

    Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.

  • CVE-2020-12926MedNov 12, 2020
    risk 0.42cvss 6.4epss 0.00

    The Trusted Platform Modules (TPM) reference software may not properly track the number of times a failed shutdown happens. This can leave the TPM in a state where confidential key material in the TPM may be able to be compromised. AMD believes that the attack requires physical…

  • CVE-2025-62619MedMay 14, 2026
    risk 0.41cvss epss 0.00

    Missing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrieve sensitive keys, potentially leading to loss of confidentiality.

  • CVE-2024-36319MedFeb 12, 2026
    risk 0.41cvss epss 0.00

    Debug code left active in AMD's Video Decoder Engine Firmware (VCN FW) could allow a attacker to submit a maliciously crafted command causing the VCN FW to perform read/writes HW registers, potentially impacting confidentiality, integrity and availabilability of the system.

  • CVE-2025-0010MedSep 6, 2025
    risk 0.40cvss 6.1epss 0.00

    An out of bounds write in the Linux graphics driver could allow an attacker to overflow the buffer potentially resulting in loss of confidentiality, integrity, or availability.

  • CVE-2023-20533MedNov 14, 2023
    risk 0.40cvss 6.1epss 0.01

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

  • CVE-2021-46758MedNov 14, 2023
    risk 0.40cvss 6.1epss 0.00

    Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.

  • CVE-2021-46759MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port,…

  • CVE-2021-46767MedJan 11, 2023
    risk 0.40cvss 6.1epss 0.00

    Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service.

  • CVE-2021-26390MedMay 10, 2022
    risk 0.40cvss 6.2epss 0.00

    A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity of data.

  • CVE-2019-1125MedSep 3, 2019
    risk 0.40cvss 5.6epss 0.05

    An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would…

  • CVE-2026-64186HigJul 19, 2026
    risk 0.39cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs In iommu_mmio_write() and iommu_capability_write(), the variables dbg_mmio_offset and dbg_cap_offset are declared as int. However, they are…

  • CVE-2025-62625MedMay 14, 2026
    risk 0.39cvss epss 0.00

    Improper privilege management in the KVM key download component could allow an attacker to swap tokens and download sensitive keys, potentially resulting in unauthorized access to privileged resources and loss of confidentiality.

  • CVE-2024-21961MedFeb 13, 2026
    risk 0.39cvss epss 0.00

    Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtual machine to potentially perform a denial of service attack against the host resulting in loss of availability.

  • CVE-2025-48508MedFeb 11, 2026
    risk 0.39cvss 6.0epss 0.00

    Improper Hardware reset flow logic in the GPU GFX Hardware IP block could allow a privileged attacker in a guest virtual machine to control reset operation potentially causing host or GPU crash or reset resulting in denial of service.

  • CVE-2025-0033MedOct 14, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentially resulting in a loss of SEV-SNP guest memory integrity.

  • CVE-2024-36346MedSep 6, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input data potentially causing a GPU Reset condition.

  • CVE-2023-31352MedFeb 11, 2025
    risk 0.39cvss 6.0epss 0.00

    A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in loss of guest private data.

  • CVE-2024-21978MedAug 5, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.

Page 6 of 11