Filtered by vendor Amd
Subscribe
Total
252 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2020-12895 | 2 Amd, Microsoft | 2 Radeon Software, Windows 10 | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
Pool/Heap Overflow in AMD Graphics Driver for Windows 10 in Escape 0x110037 may lead to escalation of privilege, information disclosure or denial of service. | |||||
CVE-2020-12894 | 2 Amd, Microsoft | 2 Radeon Software, Windows 10 | 2023-12-10 | 3.6 LOW | 7.1 HIGH |
Arbitrary Write in AMD Graphics Driver for Windows 10 in Escape 0x40010d may lead to arbitrary write to kernel memory or denial of service. | |||||
CVE-2020-12890 | 1 Amd | 1 Amd Generic Encapsulated Software Architecture | 2023-12-10 | 7.2 HIGH | 6.7 MEDIUM |
Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system. | |||||
CVE-2021-26318 | 1 Amd | 10 Athlon, Athlon Firmware, Athlon Pro and 7 more | 2023-12-10 | 1.9 LOW | 4.7 MEDIUM |
A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information. | |||||
CVE-2020-12954 | 1 Amd | 116 Epyc 7001, Epyc 7001 Firmware, Epyc 7002 and 113 more | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification. | |||||
CVE-2020-12951 | 1 Amd | 116 Epyc 7001, Epyc 7001 Firmware, Epyc 7002 and 113 more | 2023-12-10 | 4.4 MEDIUM | 7.0 HIGH |
Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations. | |||||
CVE-2020-12944 | 1 Amd | 114 Epyc 7232p, Epyc 7232p Firmware, Epyc 7251 and 111 more | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution. | |||||
CVE-2020-12893 | 2 Amd, Microsoft | 2 Radeon Software, Windows 10 | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
Stack Buffer Overflow in AMD Graphics Driver for Windows 10 in Escape 0x15002a may lead to escalation of privilege or denial of service. | |||||
CVE-2021-26315 | 1 Amd | 40 Epyc 7003, Epyc 7003 Firmware, Epyc 72f3 and 37 more | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmware images are used. | |||||
CVE-2021-26321 | 1 Amd | 114 Epyc 7232p, Epyc 7232p Firmware, Epyc 7251 and 111 more | 2023-12-10 | 4.9 MEDIUM | 5.5 MEDIUM |
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP. | |||||
CVE-2021-26336 | 1 Amd | 190 Epyc 7002, Epyc 7002 Firmware, Epyc 7003 and 187 more | 2023-12-10 | 4.9 MEDIUM | 5.5 MEDIUM |
Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other components. | |||||
CVE-2020-12964 | 1 Amd | 1 Radeon Software | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
A potential privilege escalation/denial of service issue exists in the AMD Radeon Kernel Mode driver Escape 0x2000c00 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck or write to leak information. | |||||
CVE-2020-12902 | 2 Amd, Microsoft | 2 Radeon Software, Windows 10 | 2023-12-10 | 4.6 MEDIUM | 7.8 HIGH |
Arbitrary Decrement Privilege Escalation in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service. | |||||
CVE-2020-12904 | 2 Amd, Microsoft | 2 Radeon Software, Windows 10 | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004203 may lead to arbitrary information disclosure. | |||||
CVE-2020-12960 | 2 Amd, Microsoft | 2 Radeon Software, Windows 10 | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS). | |||||
CVE-2020-12891 | 1 Amd | 2 Radeon Pro Software, Radeon Software | 2023-12-10 | 4.4 MEDIUM | 7.8 HIGH |
AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable. | |||||
CVE-2021-26329 | 1 Amd | 114 Epyc 7232p, Epyc 7232p Firmware, Epyc 7251 and 111 more | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources. | |||||
CVE-2021-26327 | 1 Amd | 40 Epyc 7003, Epyc 7003 Firmware, Epyc 72f3 and 37 more | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality. | |||||
CVE-2020-12920 | 1 Amd | 1 Radeon Software | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
A potential denial of service issue exists in the AMD Display driver Escape 0x130007 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck. | |||||
CVE-2020-12966 | 1 Amd | 214 Epyc 7001, Epyc 7001 Firmware, Epyc 7002 and 211 more | 2023-12-10 | 2.1 LOW | 5.5 MEDIUM |
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this vulnerability leading to leaking guest data by the malicious hypervisor. |