Vulnerabilities > AMD > Low

DATE CVE VULNERABILITY TITLE RISK
2021-12-10 CVE-2021-26340 Unspecified vulnerability in AMD products
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).
local
low complexity
amd
3.6
2021-11-16 CVE-2021-26337 Unspecified vulnerability in AMD products
Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.
local
low complexity
amd
2.1
2021-11-16 CVE-2021-26330 Out-of-bounds Write vulnerability in AMD products
AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.
local
low complexity
amd CWE-787
2.1
2021-11-16 CVE-2021-26327 Exposure of Resource to Wrong Sphere vulnerability in AMD products
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.
local
low complexity
amd CWE-668
2.1
2021-11-16 CVE-2021-26325 Improper Input Validation vulnerability in AMD products
Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service.
local
low complexity
amd CWE-20
2.1
2021-11-16 CVE-2021-26320 Improper Certificate Validation vulnerability in AMD products
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP
local
low complexity
amd CWE-295
2.1
2021-11-16 CVE-2020-12954 Unspecified vulnerability in AMD products
A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification.
local
low complexity
amd
2.1
2021-11-16 CVE-2021-26329 Integer Overflow or Wraparound vulnerability in AMD products
AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources.
local
low complexity
amd CWE-190
2.1
2021-11-16 CVE-2021-26312 Exposure of Resource to Wrong Sphere vulnerability in AMD products
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
local
low complexity
amd CWE-668
2.1
2021-11-15 CVE-2020-12960 Improper Input Validation vulnerability in AMD Radeon Software 20.11.2/20.7.1/21.3.1
AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS).
local
low complexity
amd CWE-20
2.1