Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2021-46744An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext EPSS 0.3%CVE-2021-26318Side-channels Related to the x86 PREFETCH InstructionEPSS 0.3%CVE-2021-46758Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapEPSS 0.3%CVE-2023-20555Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attaEPSS 0.3%CVE-2025-62619MEDIUMMissing authentication in the KVM key download endpoint could allow an unauthenticated attacker with knowledge of the exposed URL to retrievEPSS 0.3%CVE-2021-26341Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.EPSS 0.3%CVE-2024-21961MEDIUMImproper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtualEPSS 0.3%CVE-2021-46775MEDIUMImproper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading toEPSS 0.3%CVE-2020-12892An untrusted search path in AMD Radeon settings Installer may lead to a privilege escalation or unauthorized code execution.EPSS 0.3%CVE-2020-12986An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code execution in the kernel,EPSS 0.3%CVE-2020-12966AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) anEPSS 0.3%CVE-2023-20526LOWInsufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memoEPSS 0.3%CVE-2025-52534MEDIUMImproper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integritEPSS 0.3%CVE-2023-31346MEDIUMFailure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests. EPSS 0.3%CVE-2026-0481CRITICALUnrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized chEPSS 0.3%CVE-2023-20564 EPSS 0.3%CVE-2023-20591MEDIUMImproper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker toEPSS 0.3%CVE-2021-26335Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlleEPSS 0.3%CVE-2021-26331AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbiEPSS 0.3%CVE-2021-26401LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.EPSS 0.3%