← Back

Amd

amd

288 CVEs • 1,690 products

Products (1,690)

Click to collapse
Toggle

CVEs (288)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Amd
38Epyc 7001 Firmware
Epyc 7251 FirmwareEpyc 7261 Firmware+35 more
Jun 17, 2026
May 11, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush...Show more
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents. Users of SEV-ES/SEV-SNP guest VMs are not impacted by this vulnerability.Show less
1Amd
84Epyc 72f3 Firmware
Epyc 7313 FirmwareEpyc 7313p Firmware+81 more
Jun 17, 2026
May 11, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a speci...Show more
A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence that would not be generated by compilers.Show less
1Amd
23Epyc 72f3 Firmware
Epyc 7313 FirmwareEpyc 7313p Firmware+20 more
Jun 17, 2026
May 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.
1Amd
38Epyc 7001 Firmware
Epyc 7002 FirmwareEpyc 7232p Firmware+35 more
Jun 17, 2026
May 10, 2022
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.
1Amd
37Athlon 300u Firmware
Ryzen 3 3200u FirmwareRyzen 3 3300u Firmware+34 more
Jun 17, 2026
May 10, 2022
N/A· v4
6.2 MEDIUM· v3
4.9 MEDIUM· v2
A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity of data.
1Amd
49Epyc 7002 Firmware
Epyc 7232p FirmwareEpyc 7252 Firmware+46 more
Jun 17, 2026
May 10, 2022
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents re...Show more
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.Show less
1Amd
23Epyc 72f3 Firmware
Epyc 7313 FirmwareEpyc 7313p Firmware+20 more
Jun 17, 2026
May 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.
1Amd
30Ryzen 3 5300g Firmware
Ryzen 3 5300ge FirmwareRyzen 5 2600 Firmware+27 more
Jun 17, 2026
May 10, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space that could result in denial of service.
1Amd
23Epyc 72f3 Firmware
Epyc 7313 FirmwareEpyc 7313p Firmware+20 more
Jun 17, 2026
May 10, 2022
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.
1Amd
23Epyc 72f3 Firmware
Epyc 7313 FirmwareEpyc 7313p Firmware+20 more
Jun 17, 2026
May 10, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.
1Amd
126A10 9600p Firmware
A10 9630p FirmwareA12 9700p Firmware+123 more
Jun 17, 2026
Mar 11, 2022
N/A· v4
5.6 MEDIUM· v3
1.9 LOW· v2
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
1Amd
126A10 9600p Firmware
A10 9630p FirmwareA12 9700p Firmware+123 more
Jun 17, 2026
Mar 11, 2022
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
1Amd
10Xilinx Z 7007s Firmware
Xilinx Z 7010 FirmwareXilinx Z 7012s Firmware+7 more
Jun 17, 2026
Feb 10, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the ROM. Because the Zynq-7000's boot image header is unencrypted and unauthenticated before use, an attac...Show more
On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the ROM. Because the Zynq-7000's boot image header is unencrypted and unauthenticated before use, an attacker can modify the boot header stored on an SD card so that a secure image appears to be unencrypted, and they will be able to modify the full range of register initialization values. Normally, these registers will be restricted when booting securely. Of importance to this attack are two registers that control the SD card's transfer type and transfer size. These registers could be modified a way that causes a buffer overflow in the ROM.Show less
1Amd
107Epyc 7001 Firmware
Epyc 7002 FirmwareEpyc 7003 Firmware+104 more
Jun 17, 2026
Feb 4, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local a...Show more
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this vulnerability leading to leaking guest data by the malicious hypervisor.Show less
1Amd
63Athlon 3050ge Firmware
Athlon 3150g FirmwareAthlon 3150ge Firmware+60 more
Jun 17, 2026
Feb 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.
1Amd
2Radeon Pro Software
Radeon Software
Jun 17, 2026
Feb 4, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
AMD Radeon Software may be vulnerable to DLL Hijacking through path variable. An unprivileged user may be able to drop its malicious DLL file in any location which is in path environment variable.
1Amd
105Epyc 7001 Firmware
Epyc 7232p FirmwareEpyc 7251 Firmware+102 more
Jun 17, 2026
Dec 10, 2021
N/A· v4
8.4 HIGH· v3
3.6 LOW· v2
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machi...Show more
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).Show less
1Amd
1Amd Generic Encapsulated Software Architecture
Jun 17, 2026
Dec 10, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software A...Show more
Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system.Show less
1Amd
1Amd Uprof
Jun 17, 2026
Dec 1, 2021
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
The AMDPowerProfiler.sys driver of AMD μProf tool may allow lower privileged users to access MSRs in kernel which may lead to privilege escalation and ring-0 code execution by the lower privileged user.
1Amd
112Epyc 7002 Firmware
Epyc 7003 FirmwareEpyc 7232p Firmware+109 more
Jun 17, 2026
Nov 16, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.