Amd
amd
288 CVEs • 1,690 products
Products (1,690)
Click to collapseToggle
Products (1,690)
Click to collapse
CVEs (288)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Amd 34Radeon Software Ryzen 3 3100 FirmwareRyzen 3 3300g Firmware+31 moreJun 17, 2026 May 12, 2022 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure. |
1Amd 74Athlon 3050ge Firmware Athlon 3150g FirmwareAthlon 3150ge Firmware+71 moreJun 17, 2026 May 12, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution. |
1Amd 50Athlon 3050ge Firmware Athlon 3150g FirmwareAthlon 3150ge Firmware+47 moreJun 17, 2026 May 12, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses. |
1Amd 63Athlon 3050ge Firmware Athlon 3150g FirmwareAthlon 3150ge Firmware+60 moreJun 17, 2026 May 12, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity. |
1Amd 36Athlon 3050ge Firmware Athlon 3150g FirmwareAthlon 3150ge Firmware+33 moreJun 17, 2026 May 12, 2022 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive System Management Network (SMN) registers leading to a loss of integrity and availabil...Show more |
1Amd 36Athlon 3050ge Firmware Athlon 3150g FirmwareAthlon 3150ge Firmware+33 moreJun 17, 2026 May 12, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2 bootloader potentially leading to information disclosure. |
1Amd 49Ryzen 3 3100 Firmware Ryzen 3 3300g FirmwareRyzen 3 3300x Firmware+46 moreJun 17, 2026 May 12, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DRAM address that could result in denial of service. |
1Amd 99Epyc 7001 Firmware Epyc 7002 FirmwareEpyc 7003 Firmware+96 moreJun 17, 2026 May 11, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time. |
AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple processors are operating on shared memory, resulting in potential data leakage. |
1Amd 106Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+103 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service. |
1Amd 83Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+80 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service. |
1Amd 83Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+80 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service. |
1Amd 83Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+80 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service. |
1Amd 87Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+84 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service. |
1Amd 44Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+41 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service. |
1Amd 44Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+41 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service. |
1Amd 44Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+41 moreJun 17, 2026 May 11, 2022 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service. |
1Amd 23Epyc 72f3 Firmware Epyc 7313 FirmwareEpyc 7313p Firmware+20 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into trusting a dishonest Migration Agent (MA). |
1Amd 23Epyc 72f3 Firmware Epyc 7313 FirmwareEpyc 7313p Firmware+20 moreJun 17, 2026 May 11, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity. |
1Amd 49Epyc 7002 Firmware Epyc 7232p FirmwareEpyc 7252 Firmware+46 moreJun 17, 2026 May 11, 2022 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service. |