Show filters
57 Total Results
Displaying 11-20 of 57
Sort by:
Attacker Value
Unknown

CVE-2024-21925

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code execution.
0
Attacker Value
Unknown

CVE-2024-21924

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services handlers, potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown

CVE-2024-0179

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown

CVE-2023-20507

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data integrity.
0
Attacker Value
Unknown

CVE-2025-21194

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Microsoft Surface Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2024-8105

Disclosure Date: August 26, 2024 (last updated August 27, 2024)
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
0
Attacker Value
Unknown

CVE-2024-21981

Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity.
0
Attacker Value
Unknown

CVE-2023-31356

Disclosure Date: August 13, 2024 (last updated February 11, 2025)
Incomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting in a loss of data integrity.
0
Attacker Value
Unknown

CVE-2023-31310

Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.
0
Attacker Value
Unknown

CVE-2023-31305

Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure.
0