Vulnerabilities > AMD > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-20566 Unspecified vulnerability in AMD products
Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
network
low complexity
amd
7.5
2023-11-14 CVE-2023-20571 Race Condition vulnerability in AMD products
A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation.
network
high complexity
amd CWE-362
8.1
2023-11-14 CVE-2023-31320 Improper Input Validation vulnerability in AMD products
Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.
network
low complexity
amd CWE-20
7.5
2023-10-17 CVE-2023-20598 Unspecified vulnerability in AMD Radeon Software 23.7.1/23.Q3
An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution.
local
low complexity
amd
7.8
2023-08-08 CVE-2023-20555 Out-of-bounds Write vulnerability in AMD products
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.
local
low complexity
amd CWE-787
7.8
2023-08-08 CVE-2023-20562 Unspecified vulnerability in AMD Uprof 3.4.494/3.4.502
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.
local
low complexity
amd
7.8
2023-05-09 CVE-2021-46755 Unspecified vulnerability in AMD products
Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.
network
low complexity
amd
7.5
2023-05-09 CVE-2021-46765 Out-of-bounds Read vulnerability in AMD products
Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service.
network
low complexity
amd CWE-125
7.5
2023-05-09 CVE-2021-46773 Improper Input Validation vulnerability in AMD products
Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution.
network
low complexity
amd CWE-20
8.8
2023-05-09 CVE-2021-46794 Out-of-bounds Read vulnerability in AMD products
Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.
network
low complexity
amd CWE-125
7.5