Show filters
96 Total Results
Displaying 11-20 of 96
Sort by:
Attacker Value
Unknown
CVE-2023-20592
Disclosure Date: November 14, 2023 (last updated November 29, 2023)
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
0
Attacker Value
Unknown
CVE-2023-20566
Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
0
Attacker Value
Unknown
CVE-2023-20533
Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially resulting in denial-of-service.
0
Attacker Value
Unknown
CVE-2023-20526
Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
0
Attacker Value
Unknown
CVE-2023-20521
Disclosure Date: November 14, 2023 (last updated June 18, 2024)
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
0
Attacker Value
Unknown
CVE-2022-23830
Disclosure Date: November 14, 2023 (last updated June 18, 2024)
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
0
Attacker Value
Unknown
CVE-2021-46774
Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially resulting in denial-of-service.
0
Attacker Value
Unknown
CVE-2021-26345
Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
0
Attacker Value
Unknown
CVE-2023-20594
Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
0
Attacker Value
Unknown
CVE-2023-20569
Disclosure Date: August 08, 2023 (last updated April 11, 2024)
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
0