CVE-2020-12905
published 2021-11-15CVE-2020-12905: Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004403 may lead to arbitrary information disclosure.
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.25%
16.6th percentile
Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004403 may lead to arbitrary information disclosure.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | amd_radeon_software | >= Radeon Pro Software for Enterprise < 21.Q2 | 21.Q2 |
| amd | amd_radeon_software | >= Radeon Software < 20.11.2 | 20.11.2 |
| amd | radeon_software | < 20.11.2 | 20.11.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS Online Trade - Information Disclosure
suricata·2018-07-05
CVE-2018-12905 ET WEB_SPECIFIC_APPS Online Trade - Information Disclosure
ET WEB_SPECIFIC_APPS Online Trade - Information Disclosure
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Online Trade - Information Disclosure"; flow:established,to_server; http.uri; content:"/dashboard/deposit"; fast_pattern; endswith; reference:cve,2018-12905; reference:url,exploit-db.com/exploits/44977/; classtype:attempted-recon; sid:2025783; rev:3; metadata:attack_target Web_Server, created_at 2018_07_05, cve CVE_2018_12905, deployment Datacenter, performance_impact Low, signature_severity Major, updated_at 2020_09_16, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1082, mitre_technique_name System_Information_Discovery;)
No public exploits indexed.
No writeups or analysis indexed.
2021-11-15
Published