Total
396477 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-36355 | 2026-06-17 | N/A | N/A | ||
| Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify execution flow for S3 (sleep) wake up, potentially resulting in arbitrary code execution. | |||||
| CVE-2024-36354 | 2026-06-17 | N/A | 7.5 HIGH | ||
| Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in arbitrary code execution at the SMM level. | |||||
| CVE-2024-36353 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over memory values potentially leading to loss of confidentiality. | |||||
| CVE-2024-36352 | 2026-06-17 | N/A | 8.4 HIGH | ||
| Improper input validation in the AMD Graphics Driver could allow an attacker to supply a specially crafted pointer, potentially leading to arbitrary writes or denial of service. | |||||
| CVE-2024-36350 | 2026-06-17 | N/A | 5.6 MEDIUM | ||
| A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information. | |||||
| CVE-2024-36349 | 2026-06-17 | N/A | 3.8 LOW | ||
| A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage. | |||||
| CVE-2024-36348 | 2026-06-17 | N/A | 3.8 LOW | ||
| A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentially resulting in information leakage. | |||||
| CVE-2024-36347 | 2026-06-17 | N/A | 6.4 MEDIUM | ||
| Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise of SMM execution environment. | |||||
| CVE-2024-36346 | 2026-06-17 | N/A | 6.0 MEDIUM | ||
| Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input data potentially causing a GPU Reset condition. | |||||
| CVE-2024-36345 | 2026-06-17 | N/A | N/A | ||
| Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality. | |||||
| CVE-2024-36342 | 2026-06-17 | N/A | 8.8 HIGH | ||
| Improper input validation in the GPU driver could allow an attacker to exploit a heap overflow potentially resulting in arbitrary code execution. | |||||
| CVE-2024-36340 | 1 Amd | 1 Uprof | 2026-06-17 | N/A | 6.6 MEDIUM |
| A junction point vulnerability within AMD uProf can allow a local low-privileged attacker to create junction points, potentially resulting in arbitrary file deletion or disclosure. | |||||
| CVE-2024-36339 | 2026-06-17 | N/A | 7.3 HIGH | ||
| A DLL hijacking vulnerability in the AMD Optimizing CPU Libraries could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution. | |||||
| CVE-2024-36337 | 2026-06-17 | N/A | 7.9 HIGH | ||
| Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of confidentiality, integrity or availability. | |||||
| CVE-2024-36336 | 2026-06-17 | N/A | 7.9 HIGH | ||
| Integer overflow within the AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to a loss of confidentiality, integrity, or availability. | |||||
| CVE-2024-36334 | 2026-06-17 | N/A | N/A | ||
| Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory to be run with elevated privileges potentially leading to arbitrary code execution. | |||||
| CVE-2024-36333 | 1 Amd | 18 Cleanup Utility, Radeon Pro Vii, Radeon Pro W5500 and 15 more | 2026-06-17 | N/A | 7.8 HIGH |
| A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |||||
| CVE-2024-36332 | 2026-06-17 | N/A | N/A | ||
| Improper isolation of GPU HW register space could allow a privileged attacker in malicious Guest Virtual Machine (VM) to perform unauthorized access to specific victim range of GPU MMIO register space, potentially causing the host OS to reboot and creating a Denial of Service (DOS) condition. | |||||
| CVE-2024-36331 | 2026-06-17 | N/A | 3.2 LOW | ||
| Improper initialization of CPU cache memory could allow a privileged attacker with hypervisor access to overwrite SEV-SNP guest memory resulting in loss of data integrity. | |||||
| CVE-2024-36328 | 2026-06-17 | N/A | 7.3 HIGH | ||
| Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of integrity or availability. | |||||
