Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.19% | — | AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+121 | 20/9/2023 | 17/6/2026 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. | |
| Modificada | Media (6.7) | 0.30% | 💥 PoC | AMD Ryzen MasterAMD Ryzen Master Monitoring SDK | 15/8/2023 | 17/6/2026 | Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may permit a privileged attacker to perform memory reads/writes potentially leading to a loss of confidentiality or arbitrary kernel execution. | |
| Modificada | Media (4.4) | 0.22% | — | AMD Ryzen MasterAMD Ryzen Master Monitoring SDK | 15/8/2023 | 17/6/2026 | Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD Ryzen™ Master may allow a privileged attacker to provide a null value potentially resulting in a Windows crash leading to denial of service. | |
| Modificada | Media (6.8) | 0.58% | — | AMD Ryzen 5 PRO 3400g FirmwareAMD Ryzen 5 3400g FirmwareAMD Ryzen 5 PRO 3400ge FirmwareAMD Ryzen 5 PRO 3350g Firmware+118 | 8/8/2023 | 17/6/2026 | An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. | |
| Modificada | Media (5.5) | 11% | — | Debian LinuxAMD Epyc 7351p FirmwareAMD Epyc 7401p FirmwareAMD Epyc 7551p Firmware+43 | 8/8/2023 | 17/6/2026 | A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. | |
| Modificada | Crítica (9.8) | 1.00% | — | AMD Radeon Software | 8/8/2023 | 17/6/2026 | A potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson ReLive Edition falls outside of the security support lifecycle and AMD does not plan to release any mitigations | |
| Modificada | Media (4.7) | 7.3% | — | Fedoraproject FedoraDebian LinuxAMD Ryzen 9 5950x FirmwareAMD Ryzen 9 5900x Firmware+151 | 8/8/2023 | 17/6/2026 | A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. | |
| Modificada | Alta (7.8) | 0.98% | 💥 PoC | AMD Uprof | 8/8/2023 | 17/6/2026 | Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user to load an unsigned driver potentially leading to arbitrary kernel execution. | |
| Modificada | Media (5.5) | 0.27% | — | AMD Uprof | 8/8/2023 | 17/6/2026 | Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary address potentially resulting in a Windows crash leading to denial of service. | |
| Modificada | Media (5.5) | 0.27% | — | AMD Uprof | 8/8/2023 | 17/6/2026 | Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated user to send an arbitrary buffer potentially resulting in a Windows crash leading to denial of service. | |
| Modificada | Alta (7.8) | 0.32% | — | AMD Ryzen 3 3300 FirmwareAMD Ryzen 3 3300x FirmwareAMD Ryzen 5 3600 FirmwareAMD Ryzen 5 3600x Firmware+115 | 8/8/2023 | 17/6/2026 | Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM. | |
| Modificada | Media (4.7) | 0.24% | — | AMD | 1/8/2023 | 17/6/2026 | A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information. | |
| Modificada | Media (5.5) | 5.2% | 💥 PoC | XENDebian LinuxAMD Ryzen 3 3100 FirmwareAMD Ryzen 3 3300x Firmware+67 | 24/7/2023 | 17/6/2026 | An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. | |
| Modificada | Media (6.5) | 0.80% | — | AMD Epyc 7251 FirmwareAMD Epyc 7281 FirmwareAMD Epyc 7301 FirmwareAMD Epyc 7351 Firmware+84 | 11/7/2023 | 17/6/2026 | A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information. | |
| Modificada | Alta (7.5) | 1.2% | — | Amdroidapp Alarm Clock FOR Heavy Sleepers | 30/5/2023 | 17/6/2026 | An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause a denial of service attack by manipulating the database. | |
| Modificada | Crítica (9.8) | 1.2% | — | Amdroidapp Alarm Clock FOR Heavy Sleepers | 30/5/2023 | 17/6/2026 | An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the component. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+52 | 9/5/2023 | 17/6/2026 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service. | |
| Modificada | Media (5.9) | 0.40% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+51 | 9/5/2023 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service. | |
| Modificada | Alta (8.8) | 0.77% | — | AMD Ryzen 6600h FirmwareAMD Ryzen 6600hs FirmwareAMD Ryzen 6600u FirmwareAMD Ryzen 6800h Firmware+59 | 9/5/2023 | 17/6/2026 | Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Ryzen 6600h FirmwareAMD Ryzen 6600hs FirmwareAMD Ryzen 6600u FirmwareAMD Ryzen 6800h Firmware+40 | 9/5/2023 | 17/6/2026 | Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service. | |
| Modificada | Crítica (9.8) | 0.78% | — | AMD Ryzen 3945wx FirmwareAMD Ryzen 3955wx FirmwareAMD Ryzen 3960x FirmwareAMD Ryzen 3970x Firmware+3 | 9/5/2023 | 17/6/2026 | A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may potentially lead to an attacker leaking sensitive information or achieving code execution. | |
| Modificada | Media (6.1) | 0.28% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+52 | 9/5/2023 | 17/6/2026 | Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port, resulting in a potential loss of integrity. | |
| Modificada | Crítica (9.1) | 0.65% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+59 | 9/5/2023 | 17/6/2026 | Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Ryzen 5500 FirmwareAMD Ryzen 5600 FirmwareAMD Ryzen 5600g FirmwareAMD Ryzen 5600x Firmware+19 | 9/5/2023 | 17/6/2026 | Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service. | |
| Modificada | Crítica (9.1) | 0.56% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+52 | 9/5/2023 | 17/6/2026 | Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity. |