CVE-2022-29900
- EPSS 1.41%
- Published 12.07.2022 19:15:08
- Last modified 21.11.2024 06:59:55
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
CVE-2022-23823
- EPSS 0.5%
- Published 15.06.2022 20:15:17
- Last modified 21.11.2024 06:49:19
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
CVE-2021-26386
- EPSS 0.19%
- Published 12.05.2022 19:15:48
- Last modified 21.11.2024 05:56:15
A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code execution.
CVE-2021-26368
- EPSS 0.06%
- Published 12.05.2022 19:15:48
- Last modified 21.11.2024 05:56:13
Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unmap memory owned by a higher privileged process resulting in a denial of service.
CVE-2021-26317
- EPSS 0.19%
- Published 12.05.2022 19:15:48
- Last modified 21.11.2024 05:56:05
Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.
CVE-2021-26366
- EPSS 0.13%
- Published 12.05.2022 18:16:53
- Last modified 21.11.2024 05:56:13
An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.
CVE-2021-26351
- EPSS 0.13%
- Published 12.05.2022 18:16:53
- Last modified 21.11.2024 05:56:11
Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DRAM address that could result in denial of service.
CVE-2021-26378
- EPSS 0.12%
- Published 11.05.2022 17:15:08
- Last modified 21.11.2024 05:56:15
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
CVE-2021-26373
- EPSS 0.12%
- Published 11.05.2022 17:15:08
- Last modified 21.11.2024 05:56:14
Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service.
CVE-2021-26375
- EPSS 0.08%
- Published 11.05.2022 17:15:08
- Last modified 21.11.2024 05:56:14
Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.