Vulnerabilities
Vulnerable Software
Amd:  Security Vulnerabilities
The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1.
CVSS Score
9.0
EPSS Score
0.017
Published
2018-03-22
The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZENFALL-4.
CVSS Score
9.0
EPSS Score
0.017
Published
2018-03-22
The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.
CVSS Score
9.0
EPSS Score
0.017
Published
2018-03-22
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW.
CVSS Score
9.0
EPSS Score
0.018
Published
2018-03-22
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW.
CVSS Score
9.0
EPSS Score
0.018
Published
2018-03-22
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
CVSS Score
7.8
EPSS Score
0.006
Published
2017-06-07
AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.
CVSS Score
7.8
EPSS Score
0.006
Published
2017-06-07
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite.
CVSS Score
5.5
EPSS Score
0.004
Published
2017-03-25
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
CVSS Score
7.5
EPSS Score
0.016
Published
2017-02-27
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
CVSS Score
7.5
EPSS Score
0.016
Published
2017-02-27


Contact Us

Shodan ® - All rights reserved