Vulnerabilities > AMD > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-21974 Unspecified vulnerability in AMD Ryzen AI Software
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
local
low complexity
amd
7.8
2024-11-12 CVE-2024-21975 Unspecified vulnerability in AMD Ryzen AI Software
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
local
low complexity
amd
7.8
2024-02-13 CVE-2021-46757 Unspecified vulnerability in AMD products
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space potentially leading to privilege escalation.
local
low complexity
amd
7.8
2023-11-14 CVE-2021-46774 Unspecified vulnerability in AMD products
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
network
low complexity
amd
7.5
2023-11-14 CVE-2023-20533 Unspecified vulnerability in AMD products
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
network
low complexity
amd
7.5
2023-11-14 CVE-2023-20563 Improper Privilege Management vulnerability in AMD products
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
local
low complexity
amd CWE-269
7.8
2023-11-14 CVE-2023-20565 Improper Privilege Management vulnerability in AMD products
Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.
local
low complexity
amd CWE-269
7.8
2023-11-14 CVE-2023-20566 Unspecified vulnerability in AMD products
Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
network
low complexity
amd
7.5
2023-11-14 CVE-2023-20571 Race Condition vulnerability in AMD products
A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation.
network
high complexity
amd CWE-362
8.1
2023-11-14 CVE-2023-31320 Improper Input Validation vulnerability in AMD products
Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.
network
low complexity
amd CWE-20
7.5