← Back

Amd

amd

288 CVEs • 1,690 products

Products (1,690)

Click to collapse
Toggle

CVEs (288)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Amd
108Athlon 3015ce Firmware
Athlon 3015e FirmwareRyzen 3 3100 Firmware+105 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
1Amd
105Athlon 3015ce Firmware
Athlon 3015e FirmwareRyzen 3 3100 Firmware+102 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
1Amd
137Epyc 7001 Firmware
Epyc 7203 FirmwareEpyc 7203p Firmware+134 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
1Amd
28Epyc 9124 Firmware
Epyc 9174f FirmwareEpyc 9184x Firmware+25 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
1Amd
61Ryzen 3 4300u Firmware
Ryzen 3 5125c FirmwareRyzen 3 5300g Firmware+58 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity...Show more
Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity. Show less
2Amd
Intel
6Radeon Pro Vega 56 Firmware
Radeon Pro Vega 64 FirmwareRadeon Rx Vega 56 Firmware+3 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.
1Amd
90Epyc 7203 Firmware
Epyc 7203p FirmwareEpyc 7232p Firmware+87 more
Jun 17, 2026
Nov 14, 2023
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
1Amd
1Radeon Software
Jun 17, 2026
Oct 17, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a...Show more
An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execution. Show less
7Amd
AppleCanonical+4 more
16Android
Core I7 10510uCore I7 10610u+13 more
Jun 17, 2026
Sep 27, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter spec...Show more
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.Show less
1Amd
101Ryzen 3100 Firmware
Ryzen 3300x FirmwareRyzen 3500 Firmware+98 more
Jun 17, 2026
Sep 20, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
1Amd
125Epyc 7003 Firmware
Epyc 72f3 FirmwareEpyc 7313 Firmware+122 more
Jun 17, 2026
Sep 20, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
1Amd
2Ryzen Master
Ryzen Master Monitoring Sdk
Jun 17, 2026
Aug 15, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arb...Show more
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution. Show less
1Amd
2Ryzen Master
Ryzen Master Monitoring Sdk
Jun 17, 2026
Aug 15, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of...Show more
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of service. Show less
1Amd
1224700s Firmware
Athlon Gold 3150c FirmwareAthlon Gold 3150g Firmware+119 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary cod...Show more
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution.  Show less
5Amd
DebianFedoraproject+2 more
47Athlon Gold 3150g Firmware
Athlon Gold 3150ge FirmwareAthlon Gold Pro 3150g Firmware+44 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 
1Amd
1Radeon Software
Jun 17, 2026
Aug 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD...Show more
A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD does not plan to release any mitigations Show less
4Amd
DebianFedoraproject+1 more
155Debian Linux
Epyc 72f3 FirmwareEpyc 7313 Firmware+152 more
Jun 17, 2026
Aug 8, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to...Show more
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. Show less
1Amd
1Amd Uprof
Jun 17, 2026
Aug 8, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution.
1Amd
1Amd Uprof
Jun 17, 2026
Aug 8, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary address potentially resulting in a Windows crash leading to denial of serv...Show more
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary address potentially resulting in a Windows crash leading to denial of service. Show less
1Amd
1Amd Uprof
Jun 17, 2026
Aug 8, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service...Show more
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service. Show less