Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2024-21974HIGHImproper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary cEPSS 0.3%CVE-2024-21975HIGHImproper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary cEPSS 0.3%CVE-2024-21976HIGHImproper input validation in the NPU driver could allow an attacker to supply a specially crafted pointer potentially leading to arbitrary cEPSS 0.3%CVE-2020-12929Improper parameters validation in some trusted applications of the PSP contained in the AMD Graphics Driver may allow a local attacker to byEPSS 0.3%CVE-2021-26408Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in lEPSS 0.3%CVE-2020-12893Stack Buffer Overflow in AMD Graphics Driver for Windows 10 in Escape 0x15002a may lead to escalation of privilege or denial of service.EPSS 0.3%CVE-2020-12898Stack Buffer Overflow in AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.EPSS 0.3%CVE-2021-26324A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.EPSS 0.3%CVE-2021-26353Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state EPSS 0.3%CVE-2020-12901Arbitrary Free After Use in AMD Graphics Driver for Windows 10 may lead to KASLR bypass or information disclosure.EPSS 0.3%CVE-2020-12903Out of Bounds Write and Read in AMD Graphics Driver for Windows 10 in Escape 0x6002d03 may lead to escalation of privilege or denial of servEPSS 0.3%CVE-2020-12963An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows may allow unprivileged users to compromise the systeEPSS 0.3%CVE-2023-20521LOWTOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, poEPSS 0.3%CVE-2020-12982An invalid object pointer free vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of servEPSS 0.3%CVE-2020-12985An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of EPSS 0.3%CVE-2020-12983An out of bounds write vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privileges or denial of service.EPSS 0.3%CVE-2020-12962Escape call interface in the AMD Graphics Driver for Windows may cause privilege escalation.EPSS 0.3%CVE-2024-21937HIGHIncorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially EPSS 0.3%CVE-2021-26326Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.EPSS 0.3%CVE-2020-12980An out of bounds write and read vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of serEPSS 0.3%