Show filters
340 Total Results
Displaying 1-10 of 340
Sort by:
Attacker Value
Moderate
CVE-2019-5183
Disclosure Date: January 25, 2020 (last updated November 27, 2024)
An exploitable type confusion vulnerability exists in AMD ATIDXX64.DLL driver, versions 26.20.13031.10003, 26.20.13031.15006 and 26.20.13031.18002. A specially crafted pixel shader can cause a type confusion issue, leading to potential code execution. An attacker can provide a specially crafted shader file to trigger this vulnerability. This vulnerability can be triggered from VMware guest, affecting VMware host.
0
Attacker Value
High
CVE-2020-12138
Disclosure Date: April 27, 2020 (last updated November 27, 2024)
AMD ATI atillk64.sys 5.11.9.0 allows low-privileged users to interact directly with physical memory by calling one of several driver routines that map physical memory into the virtual address space of the calling process. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a DeviceIoControl call associated with MmMapIoSpace, IoAllocateMdl, MmBuildMdlForNonPagedPool, or MmMapLockedPages.
1
Attacker Value
Unknown
CVE-2024-11746
Disclosure Date: February 12, 2025 (last updated February 12, 2025)
The Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_brand' shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-21971
Disclosure Date: February 12, 2025 (last updated February 12, 2025)
Improper input validation in AMD Crash Defender could allow an attacker to provide the Windows® system process ID to a kernel-mode driver, resulting in an operating system crash, potentially leading to denial of service.
0
Attacker Value
Unknown
CVE-2023-31345
Disclosure Date: February 12, 2025 (last updated February 12, 2025)
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-20508
Disclosure Date: February 12, 2025 (last updated February 12, 2025)
Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, potentially leading to loss of confidentiality, integrity, or availability.
0
Attacker Value
Unknown
CVE-2023-31352
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in loss of guest private data.
0
Attacker Value
Unknown
CVE-2023-31343
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-31342
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-31331
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initializations, resulting in stack memory corruption that could potentially lead to loss of integrity or availability.
0