Vulnerabilities (CVE)

Filtered by vendor Amd Subscribe
Total 297 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-49121 1 Amd 1 Aiter 2026-07-15 N/A 8.1 HIGH
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote attackers to execute arbitrary code by sending a malicious pickle payload to a ZMQ SUB socket with no authentication, HMAC, or format validation. Attackers who can reach the writer XPUB endpoint on the cluster network or supply a forged Handle with an attacker-controlled remote_subscribe_addr can deliver a crafted pickle payload that executes arbitrary code simultaneously as the inference worker process on every remote reader worker.
CVE-2026-28237 1 Amd 1 Uprof 2026-06-17 N/A 5.5 MEDIUM
Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability.
CVE-2026-0466 1 Amd 1 Uprof 2026-06-17 N/A 5.5 MEDIUM
Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service.
CVE-2025-48511 1 Amd 1 Uprof 2026-06-17 N/A 5.5 MEDIUM
Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potentially resulting in crash or denial of service.
CVE-2025-48510 1 Amd 1 Uprof 2026-06-17 N/A 7.1 HIGH
Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confidentiality or availability.
CVE-2025-48502 1 Amd 1 Uprof 2026-06-17 N/A 5.5 MEDIUM
Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting in crash or denial of service.
CVE-2025-29933 1 Amd 1 Uprof 2026-06-17 N/A 5.5 MEDIUM
Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service
CVE-2024-36340 1 Amd 1 Uprof 2026-06-17 N/A 6.6 MEDIUM
A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure.
CVE-2024-36333 1 Amd 18 Cleanup Utility, Radeon Pro Vii, Radeon Pro W5500 and 15 more 2026-06-17 N/A 7.8 HIGH
A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2024-21980 1 Amd 172 Epyc 7203, Epyc 7203 Firmware, Epyc 7203p and 169 more 2026-06-17 N/A 7.9 HIGH
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
CVE-2024-21978 1 Amd 172 Epyc 7203, Epyc 7203 Firmware, Epyc 7203p and 169 more 2026-06-17 N/A 6.0 MEDIUM
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
CVE-2024-21975 1 Amd 1 Ryzen Ai Software 2026-06-17 N/A 8.8 HIGH
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
CVE-2024-21974 1 Amd 1 Ryzen Ai Software 2026-06-17 N/A 8.8 HIGH
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary code execution.
CVE-2024-21958 1 Amd 1 Provisioning Console 2026-06-17 N/A 7.3 HIGH
Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
CVE-2024-21957 1 Amd 1 Management Console 2026-06-17 N/A 7.3 HIGH
Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2024-21949 1 Amd 1 Ryzen Ai Software 2026-06-17 N/A 5.5 MEDIUM
Improper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading to system crash.
CVE-2024-21946 1 Amd 1 Ryzen Master Utility For Overclocking Control 2026-06-17 N/A 7.3 HIGH
Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2024-21945 1 Amd 1 Ryzen Master Monitoring Software Development Kit 2026-06-17 N/A 7.3 HIGH
Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2024-21939 1 Amd 1 Cloud Manageability Service 2026-06-17 N/A 7.3 HIGH
Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
CVE-2024-21938 1 Amd 1 Management Plugin For Sccm 2026-06-17 N/A 7.3 HIGH
Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directory could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.