Filtered by vendor Amd
Subscribe
Total
297 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-49121 | 1 Amd | 1 Aiter | 2026-07-15 | N/A | 8.1 HIGH |
| AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a ZMQ SUB socket with no authentication, HMAC, or format validation. Attackers who can reach the writer XPUB endpoint on the cluster network or supply a forged Handle with an attacker-controlled remote_subscribe_addr can deliver a crafted pickle payload that executes arbitrary code simultaneously as the inference worker process on every remote reader worker. | |||||
| CVE-2026-28237 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 5.5 MEDIUM |
| Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability. | |||||
| CVE-2026-0466 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service. | |||||
| CVE-2025-48511 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of service. | |||||
| CVE-2025-48510 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 7.1 HIGH |
| Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability. | |||||
| CVE-2025-48502 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service. | |||||
| CVE-2025-29933 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service | |||||
| CVE-2024-36340 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 6.6 MEDIUM |
| A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure. | |||||
| CVE-2024-36333 | 1 Amd | 18 Cleanup Utility, Radeon Pro Vii, Radeon Pro W5500 and 15 more | 2026-06-17 | N/A | 7.8 HIGH |
| A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |||||
| CVE-2024-21980 | 1 Amd | 172 Epyc 7203, Epyc 7203 Firmware, Epyc 7203p and 169 more | 2026-06-17 | N/A | 7.9 HIGH |
| Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity. | |||||
| CVE-2024-21978 | 1 Amd | 172 Epyc 7203, Epyc 7203 Firmware, Epyc 7203p and 169 more | 2026-06-17 | N/A | 6.0 MEDIUM |
| Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption. | |||||
| CVE-2024-21975 | 1 Amd | 1 Ryzen Ai Software | 2026-06-17 | N/A | 8.8 HIGH |
| Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution. | |||||
| CVE-2024-21974 | 1 Amd | 1 Ryzen Ai Software | 2026-06-17 | N/A | 8.8 HIGH |
| Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution. | |||||
| CVE-2024-21958 | 1 Amd | 1 Provisioning Console | 2026-06-17 | N/A | 7.3 HIGH |
| Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |||||
| CVE-2024-21957 | 1 Amd | 1 Management Console | 2026-06-17 | N/A | 7.3 HIGH |
| Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |||||
| CVE-2024-21949 | 1 Amd | 1 Ryzen Ai Software | 2026-06-17 | N/A | 5.5 MEDIUM |
| Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash. | |||||
| CVE-2024-21946 | 1 Amd | 1 Ryzen Master Utility For Overclocking Control | 2026-06-17 | N/A | 7.3 HIGH |
| Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |||||
| CVE-2024-21945 | 1 Amd | 1 Ryzen Master Monitoring Software Development Kit | 2026-06-17 | N/A | 7.3 HIGH |
| Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |||||
| CVE-2024-21939 | 1 Amd | 1 Cloud Manageability Service | 2026-06-17 | N/A | 7.3 HIGH |
| Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |||||
| CVE-2024-21938 | 1 Amd | 1 Management Plugin For Sccm | 2026-06-17 | N/A | 7.3 HIGH |
| Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |||||
