AMD records
302 published records for vendor amd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 19.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation47
- CWE-787 Out-of-bounds Write30
- CWE-125 Out-of-bounds Read17
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer14
- CWE-276 Incorrect Default Permissions10
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition10
The weakness classes this vendor ships most often: where to look.
CWEAll records
302 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2019-5049No exploit | An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002.amd · radeon rx 550 firmware · CWE-787 | Critical10.0 | — | 2.0% | Oct 31, 2019 |
40Plan | CVE-2020-6103No exploit | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Critical9.9 | — | 2.7% | Jul 20, 2020 |
40Plan | CVE-2020-6101No exploit | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Critical9.9 | — | 2.7% | Jul 20, 2020 |
40Plan | CVE-2020-6102No exploit | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Critical9.9 | — | 2.7% | Jul 20, 2020 |
40Plan | CVE-2019-7247No exploit | An issue was discovered in AODDriver2.sys in AMD OverDrive.amd · overdrive | Critical9.8 | — | 2.1% | May 18, 2020 |
40Plan | CVE-2020-6100No exploit | An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver.amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Critical9.9 | — | 2.0% | Jul 20, 2020 |
40Plan | CVE-2023-20591No exploit | Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker toamd · epyc 8024pn firmware · CWE-665 | Critical10.0 | — | 0.3% | Aug 13, 2024 |
39Monitor | CVE-2021-26334No exploit | AMD Chipset Driver Information Disclosure Vulnerabilityamd · amd uprof · CWE-284 | Critical9.9 | — | 1.2% | Dec 1, 2021 |
39Monitor | CVE-2023-20596No exploit | Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leadinamd · ryzen 7 5700g firmware | Critical9.8 | — | 1.0% | Nov 14, 2023 |
39Monitor | CVE-2023-20586No exploit | Radeon™ Software Crimson ReLive Editionamd · radeon software | Critical9.8 | — | 1.0% | Aug 8, 2023 |
39Monitor | CVE-2022-23821No exploit | Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execamd · ryzen 9 3900 firmware | Critical9.8 | — | 1.0% | Nov 14, 2023 |
39Monitor | CVE-2023-20520No exploit | Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun amd · epyc 72f3 firmware · CWE-787 | Critical9.8 | — | 0.8% | May 9, 2023 |
39Monitor | CVE-2021-46760No exploit | A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory accesamd · ryzen 3945wx firmware · CWE-119 | Critical9.8 | — | 0.8% | May 9, 2023 |
39Monitor | CVE-2022-23820No exploit | Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code executamd · ryzen 9 3900 firmware · CWE-20 | Critical9.8 | — | 0.7% | Nov 14, 2023 |
39Monitor | CVE-2021-26379No exploit | Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a amd · epyc 72f3 firmware | Critical9.8 | — | 0.7% | May 9, 2023 |
39Monitor | CVE-2023-39281No exploit | A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to runinsyde · insydeh2o · CWE-787 | Critical9.8 | — | 0.5% | Nov 1, 2023 |
37Monitor | CVE-2019-5183No exploit | An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031amd · atidxx64 · CWE-843 | Critical9.0 | — | 1.8% | Jan 25, 2020 |
37Monitor | CVE-2018-8930No exploit | The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERamd · ryzen mobile firmware | Critical9.0 | — | 1.8% | Mar 22, 2018 |
37Monitor | CVE-2018-8936No exploit | The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.amd · ryzen mobile firmware | Critical9.0 | — | 1.8% | Mar 22, 2018 |
37Monitor | CVE-2018-8935No exploit | The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW.amd · ryzen pro firmware | Critical9.0 | — | 1.8% | Mar 22, 2018 |
37Monitor | CVE-2018-8934No exploit | The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW.amd · ryzen pro firmware | Critical9.0 | — | 1.8% | Mar 22, 2018 |
36Monitor | CVE-2020-12138No exploit | AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routineamd · atillk64 · CWE-862 | High8.8 | — | 3.3% | Apr 27, 2020 |
36Monitor | CVE-2018-8932No exploit | The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZamd · ryzen pro firmware · CWE-732 | Critical9.0 | — | 1.7% | Mar 22, 2018 |
36Monitor | CVE-2018-8931No exploit | The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1.amd · ryzen mobile firmware · CWE-732 | Critical9.0 | — | 1.7% | Mar 22, 2018 |
36Monitor | CVE-2018-8933No exploit | The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.amd · epyc server firmware · CWE-732 | Critical9.0 | — | 1.7% | Mar 22, 2018 |
- CVE-2019-504941Plan
An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002.
CriticalCVSS 10.0No exploitEPSS 2%amd · radeon rx 550 firmwareOct 31, 2019
- CVE-2020-610340Plan
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900
CriticalCVSS 9.9No exploitEPSS 3%amd · radeon directx 11 driver atidxx64.dllJul 20, 2020
- CVE-2020-610140Plan
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900
CriticalCVSS 9.9No exploitEPSS 3%amd · radeon directx 11 driver atidxx64.dllJul 20, 2020
- CVE-2020-610240Plan
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900
CriticalCVSS 9.9No exploitEPSS 3%amd · radeon directx 11 driver atidxx64.dllJul 20, 2020
- CVE-2019-724740Plan
An issue was discovered in AODDriver2.sys in AMD OverDrive.
CriticalCVSS 9.8No exploitEPSS 2%amd · overdriveMay 18, 2020
- CVE-2020-610040Plan
An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver.
CriticalCVSS 9.9No exploitEPSS 2%amd · radeon directx 11 driver atidxx64.dllJul 20, 2020
- CVE-2023-2059140Plan
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to
CriticalCVSS 10.0No exploitEPSS 0%amd · epyc 8024pn firmwareAug 13, 2024
- CVE-2021-2633439Monitor
AMD Chipset Driver Information Disclosure Vulnerability
CriticalCVSS 9.9No exploitEPSS 1%amd · amd uprofDec 1, 2021
- CVE-2023-2059639Monitor
Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leadin
CriticalCVSS 9.8No exploitEPSS 1%amd · ryzen 7 5700g firmwareNov 14, 2023
- CVE-2023-2058639Monitor
Radeon™ Software Crimson ReLive Edition
CriticalCVSS 9.8No exploitEPSS 1%amd · radeon softwareAug 8, 2023
- CVE-2022-2382139Monitor
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code exec
CriticalCVSS 9.8No exploitEPSS 1%amd · ryzen 9 3900 firmwareNov 14, 2023
- CVE-2023-2052039Monitor
Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun
CriticalCVSS 9.8No exploitEPSS 1%amd · epyc 72f3 firmwareMay 9, 2023
- CVE-2021-4676039Monitor
A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory acces
CriticalCVSS 9.8No exploitEPSS 1%amd · ryzen 3945wx firmwareMay 9, 2023
- CVE-2022-2382039Monitor
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execut
CriticalCVSS 9.8No exploitEPSS 1%amd · ryzen 9 3900 firmwareNov 14, 2023
- CVE-2021-2637939Monitor
Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a
CriticalCVSS 9.8No exploitEPSS 1%amd · epyc 72f3 firmwareMay 9, 2023
- CVE-2023-3928139Monitor
A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run
CriticalCVSS 9.8No exploitEPSS 0%insyde · insydeh2oNov 1, 2023
- CVE-2019-518337Monitor
An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031
CriticalCVSS 9.0No exploitEPSS 2%amd · atidxx64Jan 25, 2020
- CVE-2018-893037Monitor
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTER
CriticalCVSS 9.0No exploitEPSS 2%amd · ryzen mobile firmwareMar 22, 2018
- CVE-2018-893637Monitor
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.
CriticalCVSS 9.0No exploitEPSS 2%amd · ryzen mobile firmwareMar 22, 2018
- CVE-2018-893537Monitor
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW.
CriticalCVSS 9.0No exploitEPSS 2%amd · ryzen pro firmwareMar 22, 2018
- CVE-2018-893437Monitor
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW.
CriticalCVSS 9.0No exploitEPSS 2%amd · ryzen pro firmwareMar 22, 2018
- CVE-2020-1213836Monitor
AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routine
HighCVSS 8.8No exploitEPSS 3%amd · atillk64Apr 27, 2020
- CVE-2018-893236Monitor
The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZ
CriticalCVSS 9.0No exploitEPSS 2%amd · ryzen pro firmwareMar 22, 2018
- CVE-2018-893136Monitor
The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1.
CriticalCVSS 9.0No exploitEPSS 2%amd · ryzen mobile firmwareMar 22, 2018
- CVE-2018-893336Monitor
The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.
CriticalCVSS 9.0No exploitEPSS 2%amd · epyc server firmwareMar 22, 2018