AMD / Radeon Software
52 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-36333 | A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execut… | HIGH | 7.0 | May 15, 2026 |
| CVE-2023-20548 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity,… | HIGH | 7.1 | Feb 11, 2026 |
| CVE-2023-31324 | A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify External Global Memory Interconnect Tru… | HIGH | 7.1 | Feb 11, 2026 |
| CVE-2024-21937 | Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitr… | HIGH | 7.8 | Nov 12, 2024 |
| CVE-2023-31307 | Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, poten… | MEDIUM | 4.4 | Aug 13, 2024 |
| CVE-2023-20510 | An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data cor… | MEDIUM | 6.0 | Aug 13, 2024 |
| CVE-2021-26367 | A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, pot… | MEDIUM | 6.0 | Aug 13, 2024 |
| CVE-2023-31320 | Improper input validation in the AMD RadeonTM Graphics display driver may allow an attacker to corrupt the display potentially resulting in denial of service. | HIGH | 7.5 | Nov 14, 2023 |
| CVE-2023-20568 | Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch RadeonInstaller.exe wit… | MEDIUM | 6.7 | Nov 14, 2023 |
| CVE-2023-20567 | Improper signature verification of RadeonTM RX Vega M Graphics driver for Windows may allow an attacker with admin privileges to launch AMDSoftwareInstaller.ex… | MEDIUM | 6.7 | Nov 14, 2023 |
| CVE-2021-46748 | Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Truste… | MEDIUM | 5.5 | Nov 14, 2023 |
| CVE-2023-20598 | hw: amd: AMD Radeon Graphics Kernel Driver Privilege Management Vulnerability | HIGH | 8.2 | Oct 17, 2023 |
| CVE-2023-20586 | Radeon™ Software Crimson ReLive Edition | CRITICAL | 9.8 | Aug 8, 2023 |
| CVE-2021-26392 | hw: amd: Insufficient verification in 'LoadModule' may lead to an out-of-bounds write | HIGH | 7.8 | Nov 9, 2022 |
| CVE-2021-26360 | hw: amd: Unauthorized modifications of the security configuration of the SOC registers | HIGH | 7.8 | Nov 9, 2022 |
| CVE-2020-12930 | hw: amd: Improper handling in ASP drivers leading to loss of integrity | HIGH | 7.8 | Nov 9, 2022 |
| CVE-2021-26393 | hw: amd: Insufficient memory cleanup in ASP Trusted Execution Environment (TEE) may poison process contents | MEDIUM | 5.5 | Nov 9, 2022 |
| CVE-2021-26391 | hw: amd: Insufficient verification of header signature may lead to unwanted code execution problem | HIGH | 7.8 | Nov 9, 2022 |
| CVE-2020-12931 | hw: amd: Improper handling in the ASP kernel leading to loss of integrity | HIGH | 7.8 | Nov 9, 2022 |
| CVE-2021-26363 | A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potential… | MEDIUM | 4.4 | May 12, 2022 |
| CVE-2021-26317 | Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution. | HIGH | 7.8 | May 12, 2022 |
| CVE-2021-26361 | A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2… | MEDIUM | 5.5 | May 12, 2022 |
| CVE-2021-26362 | A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive System Management Network… | HIGH | 7.1 | May 12, 2022 |
| CVE-2021-26366 | An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity. | HIGH | 7.1 | May 12, 2022 |
| CVE-2021-26369 | A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses. | HIGH | 7.8 | May 12, 2022 |
Showing 1 to 25 of 52 CVEs