← Back

Amd

amd

288 CVEs • 1,690 products

Products (1,690)

Click to collapse
Toggle

CVEs (288)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Amd
34Radeon Software
Ryzen 3 3100 FirmwareRyzen 3 3300g Firmware+31 more
Jun 17, 2026
May 12, 2022
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.
1Amd
74Athlon 3050ge Firmware
Athlon 3150g FirmwareAthlon 3150ge Firmware+71 more
Jun 17, 2026
May 12, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.
1Amd
50Athlon 3050ge Firmware
Athlon 3150g FirmwareAthlon 3150ge Firmware+47 more
Jun 17, 2026
May 12, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.
1Amd
63Athlon 3050ge Firmware
Athlon 3150g FirmwareAthlon 3150ge Firmware+60 more
Jun 17, 2026
May 12, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.
1Amd
36Athlon 3050ge Firmware
Athlon 3150g FirmwareAthlon 3150ge Firmware+33 more
Jun 17, 2026
May 12, 2022
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive System Management Network (SMN) registers leading to a loss of integrity and availabil...Show more
A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive System Management Network (SMN) registers leading to a loss of integrity and availability.Show less
1Amd
36Athlon 3050ge Firmware
Athlon 3150g FirmwareAthlon 3150ge Firmware+33 more
Jun 17, 2026
May 12, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2 bootloader potentially leading to information disclosure.
1Amd
49Ryzen 3 3100 Firmware
Ryzen 3 3300g FirmwareRyzen 3 3300x Firmware+46 more
Jun 17, 2026
May 12, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DRAM address that could result in denial of service.
1Amd
99Epyc 7001 Firmware
Epyc 7002 FirmwareEpyc 7003 Firmware+96 more
Jun 17, 2026
May 11, 2022
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
1Amd
1Cpu
Jun 17, 2026
May 11, 2022
N/A· v4
4.0 MEDIUM· v3
2.1 LOW· v2
AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple processors are operating on shared memory, resulting in potential data leakage.
1Amd
106Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+103 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.
1Amd
83Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+80 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
1Amd
83Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+80 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service.
1Amd
83Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+80 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.
1Amd
87Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+84 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service.
1Amd
44Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+41 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
1Amd
44Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+41 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service.
1Amd
44Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+41 more
Jun 17, 2026
May 11, 2022
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.
1Amd
23Epyc 72f3 Firmware
Epyc 7313 FirmwareEpyc 7313p Firmware+20 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into trusting a dishonest Migration Agent (MA).
1Amd
23Epyc 72f3 Firmware
Epyc 7313 FirmwareEpyc 7313p Firmware+20 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
1Amd
49Epyc 7002 Firmware
Epyc 7232p FirmwareEpyc 7252 Firmware+46 more
Jun 17, 2026
May 11, 2022
N/A· v4
4.7 MEDIUM· v3
4.7 MEDIUM· v2
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.