CVE-2024-36353
- EPSS 0.03%
- Published 02.03.2025 18:15:34
- Last modified 25.09.2025 20:15:33
Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over memory values potentially leading to loss of confidentiality.
CVE-2024-21937
- EPSS 0.02%
- Published 12.11.2024 18:15:17
- Last modified 27.11.2024 16:20:37
Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2023-31307
- EPSS 0.06%
- Published 13.08.2024 17:15:20
- Last modified 13.12.2024 16:30:30
Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.
- EPSS 0.03%
- Published 13.08.2024 17:15:18
- Last modified 12.12.2024 20:28:55
An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.
- EPSS 0.04%
- Published 13.08.2024 17:15:17
- Last modified 12.12.2024 20:41:56
A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability.
CVE-2023-31320
- EPSS 6.64%
- Published 14.11.2023 19:15:25
- Last modified 21.11.2024 08:01:46
Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service.
CVE-2023-20568
- EPSS 0.03%
- Published 14.11.2023 19:15:15
- Last modified 13.02.2025 17:16:01
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe without validating the file signature potentially leading to arbitrary code execution.
CVE-2023-20567
- EPSS 0.03%
- Published 14.11.2023 19:15:15
- Last modified 13.02.2025 17:16:01
Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.exe without validating the file signature potentially leading to arbitrary code execution.
CVE-2021-46748
- EPSS 0.1%
- Published 14.11.2023 19:15:10
- Last modified 13.02.2025 17:15:34
Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.
CVE-2023-20598
- EPSS 1.47%
- Published 17.10.2023 14:15:09
- Last modified 21.11.2024 07:41:12
An improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control over arbitrary hardware ports or physical addresses resulting in a potential arbitrary code execu...