Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown

CVE-2023-20519

Disclosure Date: November 14, 2023 (last updated November 22, 2023)
A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.
Attacker Value
Unknown

CVE-2023-20594

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Attacker Value
Unknown

CVE-2021-46756

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity.
Attacker Value
Unknown

CVE-2023-20524

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.
Attacker Value
Unknown

CVE-2023-20520

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2022-23818

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.
Attacker Value
Unknown

CVE-2021-46775

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution.
Attacker Value
Unknown

CVE-2021-46769

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution.
Attacker Value
Unknown

CVE-2021-46764

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.
Attacker Value
Unknown

CVE-2021-46763

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity.