CVE-2021-26356
- EPSS 0.19%
- Veröffentlicht 09.05.2023 19:15:10
- Zuletzt bearbeitet 28.01.2025 16:15:29
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
CVE-2021-26354
- EPSS 0.05%
- Veröffentlicht 09.05.2023 19:15:10
- Zuletzt bearbeitet 28.01.2025 16:15:27
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.
CVE-2023-20559
- EPSS 0.39%
- Veröffentlicht 02.04.2023 21:15:08
- Zuletzt bearbeitet 25.02.2025 17:15:11
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
CVE-2023-20558
- EPSS 0.39%
- Veröffentlicht 02.04.2023 21:15:08
- Zuletzt bearbeitet 20.02.2025 20:15:44
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
CVE-2022-27672
- EPSS 0.23%
- Veröffentlicht 01.03.2023 08:15:10
- Zuletzt bearbeitet 13.04.2026 20:16:23
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.
CVE-2022-23824
- EPSS 0.04%
- Veröffentlicht 09.11.2022 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:49:19
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
CVE-2021-26392
- EPSS 0.14%
- Veröffentlicht 09.11.2022 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:56:16
Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.
CVE-2020-12931
- EPSS 0.15%
- Veröffentlicht 09.11.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:00:33
Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
CVE-2020-12930
- EPSS 0.15%
- Veröffentlicht 09.11.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:00:33
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
CVE-2021-46778
- EPSS 0.12%
- Veröffentlicht 10.08.2022 20:15:24
- Zuletzt bearbeitet 21.11.2024 06:34:42
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues ...