Vulnerabilities > AMD > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-17 CVE-2023-20598 Unspecified vulnerability in AMD Radeon Software 23.7.1/23.Q3
An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution.
local
low complexity
amd
7.8
2023-08-08 CVE-2023-20555 Out-of-bounds Write vulnerability in AMD products
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.
local
low complexity
amd CWE-787
7.8
2023-08-08 CVE-2023-20562 Unspecified vulnerability in AMD Uprof 3.4.494/3.4.502
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.
local
low complexity
amd
7.8
2023-05-09 CVE-2021-46755 Unspecified vulnerability in AMD products
Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.
network
low complexity
amd
7.5
2023-05-09 CVE-2021-46765 Out-of-bounds Read vulnerability in AMD products
Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service.
network
low complexity
amd CWE-125
7.5
2023-05-09 CVE-2021-46773 Improper Input Validation vulnerability in AMD products
Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution.
network
low complexity
amd CWE-20
8.8
2023-05-09 CVE-2021-46794 Out-of-bounds Read vulnerability in AMD products
Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.
network
low complexity
amd CWE-125
7.5
2023-05-09 CVE-2021-26356 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in AMD products
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
network
high complexity
amd CWE-367
7.4
2023-05-09 CVE-2021-26365 Out-of-bounds Read vulnerability in AMD products
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.
network
low complexity
amd CWE-125
8.2
2023-05-09 CVE-2021-26397 Unspecified vulnerability in AMD products
Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability.
local
low complexity
amd
7.1