AMD kayıtları
amd üreticisine ait 302 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %19,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation47
- CWE-787 Out-of-bounds Write30
- CWE-125 Out-of-bounds Read17
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer14
- CWE-276 Incorrect Default Permissions10
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition10
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
302 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2019-5049İstismar yok | An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002.amd · radeon rx 550 firmware · CWE-787 | Kritik10,0 | — | %2,0 | 31 Eki 2019 |
40Planlayın | CVE-2020-6103İstismar yok | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Kritik9,9 | — | %2,7 | 20 Tem 2020 |
40Planlayın | CVE-2020-6101İstismar yok | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Kritik9,9 | — | %2,7 | 20 Tem 2020 |
40Planlayın | CVE-2020-6102İstismar yok | An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Kritik9,9 | — | %2,7 | 20 Tem 2020 |
40Planlayın | CVE-2019-7247İstismar yok | An issue was discovered in AODDriver2.sys in AMD OverDrive.amd · overdrive | Kritik9,8 | — | %2,1 | 18 May 2020 |
40Planlayın | CVE-2020-6100İstismar yok | An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver.amd · radeon directx 11 driver atidxx64.dll · CWE-787 | Kritik9,9 | — | %2,0 | 20 Tem 2020 |
40Planlayın | CVE-2023-20591İstismar yok | Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker toamd · epyc 8024pn firmware · CWE-665 | Kritik10,0 | — | %0,3 | 13 Ağu 2024 |
39İzleyin | CVE-2021-26334İstismar yok | AMD Chipset Driver Information Disclosure Vulnerabilityamd · amd uprof · CWE-284 | Kritik9,9 | — | %1,2 | 1 Ara 2021 |
39İzleyin | CVE-2023-20596İstismar yok | Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leadinamd · ryzen 7 5700g firmware | Kritik9,8 | — | %1,0 | 14 Kas 2023 |
39İzleyin | CVE-2023-20586İstismar yok | Radeon™ Software Crimson ReLive Editionamd · radeon software | Kritik9,8 | — | %1,0 | 8 Ağu 2023 |
39İzleyin | CVE-2022-23821İstismar yok | Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execamd · ryzen 9 3900 firmware | Kritik9,8 | — | %1,0 | 14 Kas 2023 |
39İzleyin | CVE-2023-20520İstismar yok | Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun amd · epyc 72f3 firmware · CWE-787 | Kritik9,8 | — | %0,8 | 9 May 2023 |
39İzleyin | CVE-2021-46760İstismar yok | A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory accesamd · ryzen 3945wx firmware · CWE-119 | Kritik9,8 | — | %0,8 | 9 May 2023 |
39İzleyin | CVE-2022-23820İstismar yok | Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code executamd · ryzen 9 3900 firmware · CWE-20 | Kritik9,8 | — | %0,7 | 14 Kas 2023 |
39İzleyin | CVE-2021-26379İstismar yok | Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a amd · epyc 72f3 firmware | Kritik9,8 | — | %0,7 | 9 May 2023 |
39İzleyin | CVE-2023-39281İstismar yok | A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to runinsyde · insydeh2o · CWE-787 | Kritik9,8 | — | %0,5 | 1 Kas 2023 |
37İzleyin | CVE-2019-5183İstismar yok | An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031amd · atidxx64 · CWE-843 | Kritik9,0 | — | %1,8 | 25 Oca 2020 |
37İzleyin | CVE-2018-8930İstismar yok | The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERamd · ryzen mobile firmware | Kritik9,0 | — | %1,8 | 22 Mar 2018 |
37İzleyin | CVE-2018-8936İstismar yok | The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.amd · ryzen mobile firmware | Kritik9,0 | — | %1,8 | 22 Mar 2018 |
37İzleyin | CVE-2018-8935İstismar yok | The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW.amd · ryzen pro firmware | Kritik9,0 | — | %1,8 | 22 Mar 2018 |
37İzleyin | CVE-2018-8934İstismar yok | The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW.amd · ryzen pro firmware | Kritik9,0 | — | %1,8 | 22 Mar 2018 |
36İzleyin | CVE-2020-12138İstismar yok | AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routineamd · atillk64 · CWE-862 | Yüksek8,8 | — | %3,3 | 27 Nis 2020 |
36İzleyin | CVE-2018-8932İstismar yok | The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZamd · ryzen pro firmware · CWE-732 | Kritik9,0 | — | %1,7 | 22 Mar 2018 |
36İzleyin | CVE-2018-8931İstismar yok | The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1.amd · ryzen mobile firmware · CWE-732 | Kritik9,0 | — | %1,7 | 22 Mar 2018 |
36İzleyin | CVE-2018-8933İstismar yok | The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.amd · epyc server firmware · CWE-732 | Kritik9,0 | — | %1,7 | 22 Mar 2018 |
- CVE-2019-504941Planlayın
An exploitable memory corruption vulnerability exists in AMD ATIDXX64.DLL driver, versions 25.20.15031.5004 and 25.20.15031.9002.
KritikCVSS 10,0İstismar yokEPSS %2amd · radeon rx 550 firmware31 Eki 2019
- CVE-2020-610340Planlayın
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900
KritikCVSS 9,9İstismar yokEPSS %3amd · radeon directx 11 driver atidxx64.dll20 Tem 2020
- CVE-2020-610140Planlayın
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900
KritikCVSS 9,9İstismar yokEPSS %3amd · radeon directx 11 driver atidxx64.dll20 Tem 2020
- CVE-2020-610240Planlayın
An exploitable code execution vulnerability exists in the Shader functionality of AMD Radeon DirectX 11 Driver atidxx64.dll 26.20.15019.1900
KritikCVSS 9,9İstismar yokEPSS %3amd · radeon directx 11 driver atidxx64.dll20 Tem 2020
- CVE-2019-724740Planlayın
An issue was discovered in AODDriver2.sys in AMD OverDrive.
KritikCVSS 9,8İstismar yokEPSS %2amd · overdrive18 May 2020
- CVE-2020-610040Planlayın
An exploitable memory corruption vulnerability exists in AMD atidxx64.dll 26.20.15019.19000 graphics driver.
KritikCVSS 9,9İstismar yokEPSS %2amd · radeon directx 11 driver atidxx64.dll20 Tem 2020
- CVE-2023-2059140Planlayın
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to
KritikCVSS 10,0İstismar yokEPSS %0amd · epyc 8024pn firmware13 Ağu 2024
- CVE-2021-2633439İzleyin
AMD Chipset Driver Information Disclosure Vulnerability
KritikCVSS 9,9İstismar yokEPSS %1amd · amd uprof1 Ara 2021
- CVE-2023-2059639İzleyin
Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leadin
KritikCVSS 9,8İstismar yokEPSS %1amd · ryzen 7 5700g firmware14 Kas 2023
- CVE-2023-2058639İzleyin
Radeon™ Software Crimson ReLive Edition
KritikCVSS 9,8İstismar yokEPSS %1amd · radeon software8 Ağu 2023
- CVE-2022-2382139İzleyin
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code exec
KritikCVSS 9,8İstismar yokEPSS %1amd · ryzen 9 3900 firmware14 Kas 2023
- CVE-2023-2052039İzleyin
Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun
KritikCVSS 9,8İstismar yokEPSS %1amd · epyc 72f3 firmware9 May 2023
- CVE-2021-4676039İzleyin
A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory acces
KritikCVSS 9,8İstismar yokEPSS %1amd · ryzen 3945wx firmware9 May 2023
- CVE-2022-2382039İzleyin
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execut
KritikCVSS 9,8İstismar yokEPSS %1amd · ryzen 9 3900 firmware14 Kas 2023
- CVE-2021-2637939İzleyin
Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a
KritikCVSS 9,8İstismar yokEPSS %1amd · epyc 72f3 firmware9 May 2023
- CVE-2023-3928139İzleyin
A stack buffer overflow vulnerability discovered in AsfSecureBootDxe in Insyde InsydeH2O with kernel 5.0 through 5.5 allows attackers to run
KritikCVSS 9,8İstismar yokEPSS %0insyde · insydeh2o1 Kas 2023
- CVE-2019-518337İzleyin
An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031
KritikCVSS 9,0İstismar yokEPSS %2amd · atidxx6425 Oca 2020
- CVE-2018-893037İzleyin
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTER
KritikCVSS 9,0İstismar yokEPSS %2amd · ryzen mobile firmware22 Mar 2018
- CVE-2018-893637İzleyin
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.
KritikCVSS 9,0İstismar yokEPSS %2amd · ryzen mobile firmware22 Mar 2018
- CVE-2018-893537İzleyin
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW.
KritikCVSS 9,0İstismar yokEPSS %2amd · ryzen pro firmware22 Mar 2018
- CVE-2018-893437İzleyin
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW.
KritikCVSS 9,0İstismar yokEPSS %2amd · ryzen pro firmware22 Mar 2018
- CVE-2020-1213836İzleyin
AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routine
YüksekCVSS 8,8İstismar yokEPSS %3amd · atillk6427 Nis 2020
- CVE-2018-893236İzleyin
The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZ
KritikCVSS 9,0İstismar yokEPSS %2amd · ryzen pro firmware22 Mar 2018
- CVE-2018-893136İzleyin
The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1.
KritikCVSS 9,0İstismar yokEPSS %2amd · ryzen mobile firmware22 Mar 2018
- CVE-2018-893336İzleyin
The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.
KritikCVSS 9,0İstismar yokEPSS %2amd · epyc server firmware22 Mar 2018