Latest CVE Feed
-
7.8
HIGHCVE-2021-26331
AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.... Read more
Affected Products : epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware epyc_7542_firmware +106 more products- EPSS Score: %0.05
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26330
AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.... Read more
Affected Products : epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware epyc_7542_firmware +106 more products- EPSS Score: %0.05
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26329
AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources.... Read more
Affected Products : epyc_7h12_firmware epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware +104 more products- EPSS Score: %0.05
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26327
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of guest confidentiality.... Read more
Affected Products : epyc_7003_firmware epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware epyc_7443p_firmware epyc_7453_firmware +30 more products- EPSS Score: %0.06
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26326
Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.... Read more
Affected Products : epyc_7232p_firmware epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware epyc_7443p_firmware epyc_7453_firmware +30 more products- EPSS Score: %0.05
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26325
Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service.... Read more
Affected Products : epyc_7232p_firmware epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware epyc_7443p_firmware epyc_7453_firmware +30 more products- EPSS Score: %0.05
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26324
A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.... Read more
Affected Products : epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_7373x_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware epyc_7443p_firmware epyc_7453_firmware +36 more products- EPSS Score: %0.04
- Published: May. 10, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26323
Failure to validate SEV Commands while SNP is active may result in a potential impact to memory integrity.... Read more
Affected Products : epyc_7232p_firmware epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware epyc_7443p_firmware epyc_7453_firmware +30 more products- EPSS Score: %0.06
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26322
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.... Read more
Affected Products : epyc_7h12_firmware epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware +104 more products- EPSS Score: %0.40
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26321
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.... Read more
Affected Products : epyc_7h12_firmware epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware +104 more products- EPSS Score: %0.15
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26320
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP... Read more
Affected Products : epyc_7h12_firmware epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware +104 more products- EPSS Score: %0.04
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2021-26318
A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information.... Read more
Affected Products : athlon_firmware athlon_pro_firmware epyc_firmware ryzen_firmware ryzen_pro_firmware ryzen_pro ryzen athlon athlon_pro epyc- EPSS Score: %0.11
- Published: Oct. 13, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26317
Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.... Read more
- EPSS Score: %0.19
- Published: May. 12, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-26315
When the AMD Platform Security Processor (PSP) boot rom loads, authenticates, and subsequently decrypts an encrypted FW, due to insufficient verification of the integrity of decrypted image, arbitrary code may be executed in the PSP when encrypted firmwar... Read more
Affected Products : epyc_7003_firmware epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware epyc_7443p_firmware epyc_7453_firmware +30 more products- EPSS Score: %0.03
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26314
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in d... Read more
Affected Products : fedora xen cortex-a72 bcm2711 core_i7-10700k core_i7-7700k core_i9-9900k xeon_silver_4214 ryzen_5_5600x ryzen_threadripper_2990wx +1 more products- EPSS Score: %0.10
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26313
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.... Read more
Affected Products : debian_linux xen cortex-a72 bcm2711 core_i7-10700k core_i7-7700k core_i9-9900k xeon_silver_4214 ryzen_5_5600x ryzen_threadripper_2990wx +1 more products- EPSS Score: %0.08
- Published: Jun. 09, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-26312
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.... Read more
Affected Products : epyc_7h12_firmware epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware epyc_7552_firmware +104 more products- EPSS Score: %0.05
- Published: Nov. 16, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-26311
In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a mal... Read more
- EPSS Score: %1.28
- Published: May. 13, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-26310
In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.... Read more
Affected Products : teamcity- EPSS Score: %0.00
- Published: May. 11, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2021-26309
Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary file had Insecure Permissions.... Read more
Affected Products : teamcity- EPSS Score: %0.00
- Published: May. 11, 2021
- Modified: Nov. 21, 2024