← Back

Amd

amd

288 CVEs • 1,690 products

Products (1,690)

Click to collapse
Toggle

CVEs (288)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Amd
1Uprof
Jun 17, 2026
Jun 9, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability.
1Amd
1Uprof
Jun 17, 2026
Jun 9, 2026
6.8 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service.
1Amd
1Aiter
Jul 22, 2026
Jun 1, 2026
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to...Show more
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a ZMQ SUB socket with no authentication, HMAC, or format validation. Attackers who can reach the writer XPUB endpoint on the cluster network or supply a forged Handle with an attacker-controlled remote_subscribe_addr can deliver a crafted pickle payload that executes arbitrary code simultaneously as the inference worker process on every remote reader worker.Show less
1Amd
2Cleanup Utility
Radeon Software
Jun 17, 2026
May 15, 2026
7.0 HIGH· v4
7.8 HIGH· v3
N/A· v2
A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
1Amd
4Radeon Pro Vii Firmware
Radeon SoftwareRadeon Vii Firmware+1 more
Jun 17, 2026
Feb 11, 2026
7.1 HIGH· v4
7.8 HIGH· v3
N/A· v2
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potential...Show more
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Trusted Agent (XGMI TA) commands as they are processed potentially resulting in loss of confidentiality, integrity, or availability.Show less
1Amd
4Radeon Pro Vii Firmware
Radeon SoftwareRadeon Vii Firmware+1 more
Jun 17, 2026
Feb 11, 2026
7.1 HIGH· v4
7.8 HIGH· v3
N/A· v2
A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.
1Amd
1Uprof
Jun 17, 2026
Nov 24, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of service.
1Amd
1Uprof
Jun 17, 2026
Nov 24, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability.
1Amd
1Uprof
Jun 17, 2026
Nov 24, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service
1Amd
1Uprof
Jun 17, 2026
Nov 21, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service.
1Amd
1Aim T Manageability Api
Jun 17, 2026
May 13, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect default permissions in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
1Amd
1Aim T Manageability Api
Jun 17, 2026
May 13, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
A DLL hijacking vulnerability in the AMD Manageability API could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
1Amd
1Uprof
Jun 17, 2026
May 13, 2025
N/A· v4
6.6 MEDIUM· v3
N/A· v2
A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.
1Amd
1Ryzen Ai Software
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
1Amd
1Ryzen Ai Software
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
1Amd
1Provisioning Console
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
1Amd
1Management Console
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
1Amd
1Ryzen Ai Software
Jun 17, 2026
Nov 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.
1Amd
1Ryzen Master Utility For Overclocking Control
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
1Amd
1Ryzen Master Monitoring Software Development Kit
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.