VYPR

Vendor CVEs

AMD

All CVEs

517 total · sorted by risk
  • CVE-2023-44216MedSep 27, 2023
    risk 0.35cvss 5.3epss 0.02

    PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can…

  • CVE-2019-9836MedJun 25, 2019
    risk 0.35cvss 5.3epss 0.02

    Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.

  • CVE-2025-54511MedMay 15, 2026
    risk 0.34cvss epss 0.00

    Improper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a function without sufficient privileges and successfully write data, potentially resulting in loss of integrity of availability.

  • CVE-2025-0040MedMay 15, 2026
    risk 0.34cvss epss 0.00

    Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow an attacker with physical access to read or overwrite the contents of cross-chip debug (XCD) registers potentially resulting in loss of data integrity or…

  • CVE-2025-52534MedFeb 10, 2026
    risk 0.34cvss epss 0.00

    Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity.

  • CVE-2025-29934MedNov 21, 2025
    risk 0.34cvss 5.3epss 0.00

    A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries, potentially resulting in loss of data integrity.

  • CVE-2023-31351MedSep 6, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper restriction of operations in the IOMMU could allow a malicious hypervisor to access guest private memory resulting in loss of integrity.

  • CVE-2023-20582MedFeb 11, 2025
    risk 0.34cvss 5.3epss 0.00

    Improper handling of invalid nested page table entries in the IOMMU may allow a privileged attacker to induce page table entry (PTE) faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest memory integrity.

  • CVE-2023-20584MedAug 13, 2024
    risk 0.34cvss 5.3epss 0.00

    IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity.

  • CVE-2023-20509MedAug 13, 2024
    risk 0.34cvss 5.2epss 0.00

    An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially resulting in loss of data integrity.

  • CVE-2021-46746MedAug 13, 2024
    risk 0.34cvss 5.2epss 0.00

    Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to a denial of service.

  • CVE-2024-21979MedApr 23, 2024
    risk 0.34cvss 5.3epss 0.00

    An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformed shader to potentially achieve arbitrary code execution.

  • CVE-2024-21972MedApr 23, 2024
    risk 0.34cvss 5.3epss 0.00

    An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformed shader to potentially achieve arbitrary code execution.

  • CVE-2023-20566MedNov 14, 2023
    risk 0.34cvss 5.3epss 0.00

    Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.

  • CVE-2023-20532MedJan 11, 2023
    risk 0.34cvss 5.3epss 0.01

    Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.

  • CVE-2022-23814MedJan 11, 2023
    risk 0.34cvss 5.3epss 0.00

    Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment.

  • CVE-2022-23813MedJan 11, 2023
    risk 0.34cvss 5.3epss 0.01

    The software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest memory in a confidential compute environment.

  • CVE-2024-21935MedSep 23, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local root directory, potentially resulting in data corruption.

  • CVE-2024-21927MedSep 23, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to use certain special characters in manipulated Redfish® API commands, causing service processes like OpenBMC to crash and reset, potentially resulting in denial of service.

  • CVE-2023-20508MedFeb 12, 2025
    risk 0.33cvss 5.0epss 0.00

    Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, potentially leading to loss of confidentiality, integrity, or availability.

  • CVE-2023-31310MedAug 13, 2024
    risk 0.33cvss 5.0epss 0.00

    Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.

  • CVE-2023-31347MedFeb 13, 2024
    risk 0.32cvss 4.9epss 0.00

    Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.  

  • CVE-2025-0044MedMay 15, 2026
    risk 0.31cvss epss 0.00

    An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially lead to a partial loss of confidentiality and availability.

  • CVE-2025-54514MedFeb 10, 2026
    risk 0.31cvss epss 0.00

    Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could potentially lead to a partial loss of integrity.

  • CVE-2025-29949MedFeb 10, 2026
    risk 0.31cvss epss 0.00

    Insufficient input parameter sanitization in AMD Secure Processor (ASP) Boot Loader (legacy recovery mode only) could allow an attacker to write out-of-bounds to corrupt Secure DRAM potentially resulting in denial of service.

  • CVE-2025-0034MedSep 6, 2025
    risk 0.31cvss 4.7epss 0.00

    Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_SPATIAL_PART and cause read or write past the end of allocated arrays, potentially resulting in a loss of platform integrity or denial of service.

  • CVE-2023-31339MedAug 13, 2024
    risk 0.31cvss 4.8epss 0.00

    Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.

  • CVE-2023-20510MedAug 13, 2024
    risk 0.31cvss 4.7epss 0.00

    An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.

  • CVE-2023-20569MedAug 8, 2023
    risk 0.31cvss 4.7epss 0.07

    A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.

  • CVE-2023-20583MedAug 1, 2023
    risk 0.31cvss 4.7epss 0.00

    A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.

  • CVE-2022-27672MedMar 1, 2023
    risk 0.31cvss 4.7epss 0.00

    When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.

  • CVE-2021-46795MedJan 11, 2023
    risk 0.31cvss 4.7epss 0.00

    A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of service.

  • CVE-2021-26350MedMay 11, 2022
    risk 0.31cvss 4.7epss 0.00

    A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.

  • CVE-2021-26347MedMay 11, 2022
    risk 0.31cvss 4.7epss 0.00

    Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

  • CVE-2021-26318MedOct 13, 2021
    risk 0.31cvss 4.7epss 0.00

    A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information.

  • CVE-2025-48506MedAug 11, 2026
    risk 0.30cvss epss 0.00

    Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.

  • CVE-2025-0041MedAug 11, 2026
    risk 0.30cvss epss 0.00

    Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.

  • CVE-2024-36343MedMay 19, 2026
    risk 0.30cvss epss 0.00

    Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited section of the Top of Memory Segment (TSEG) memory region, potentially resulting in loss of…

  • CVE-2026-0427MedMay 15, 2026
    risk 0.30cvss epss 0.00

    Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources from another Guest VM, potentially resulting in the loss of confidentiality, integrity, or availability.

  • CVE-2025-66664MedMay 15, 2026
    risk 0.30cvss epss 0.00

    Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_LOAD_GFX_IP_FW SR-IOV command to cause out-of-bounds read, potentially resulting in SOC Driver memory contents exposure or an exception

  • CVE-2024-36345MedMay 15, 2026
    risk 0.30cvss epss 0.00

    Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality.

  • CVE-2023-20601MedFeb 12, 2026
    risk 0.30cvss epss 0.00

    Improper input validation within RAS TA Driver can allow a local attacker to access out-of-bounds memory, potentially resulting in a denial-of-service condition.

  • CVE-2025-48517MedFeb 10, 2026
    risk 0.30cvss epss 0.00

    Insufficient Granularity of Access Control in SEV firmware could allow a privileged user with a malicious hypervisor to create a SEV-ES guest with an ASID in the range meant for SEV-SNP guests potentially resulting in a partial loss of confidentiality.

  • CVE-2025-0031MedFeb 10, 2026
    risk 0.30cvss epss 0.00

    A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity.

  • CVE-2024-36311MedFeb 10, 2026
    risk 0.30cvss epss 0.00

    A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality, integrity, or availability.

  • CVE-2024-36310MedFeb 10, 2026
    risk 0.30cvss epss 0.00

    Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of confidentiality or integrity.

  • CVE-2025-29943MedJan 16, 2026
    risk 0.30cvss epss 0.00

    Write what were condition within AMD CPUs may allow an admin-privileged attacker to modify the configuration of the CPU pipeline potentially resulting in the corruption of the stack pointer inside an SEV-SNP guest.

  • CVE-2025-29946MedFeb 10, 2026
    risk 0.29cvss epss 0.00

    Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory.

  • CVE-2024-21970MedSep 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity.

  • CVE-2023-31356MedAug 13, 2024
    risk 0.29cvss 4.4epss 0.00

    Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.