Amd Radeon Software vulnerabilities
45 known vulnerabilities affecting amd/radeon_software.
Total CVEs
45
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH31MEDIUM14
Vulnerabilities
Page 3 of 3
CVE-2020-12897P4MEDIUMCVSS 5.5fixed in 21.3.12021-11-15
CVE-2020-12897 [MEDIUM] CVE-2020-12897: Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass.
Kernel Pool Address disclosure in AMD Graphics Driver for Windows 10 may lead to KASLR bypass.
nvd
CVE-2021-46748P4MEDIUMCVSS 5.5fixed in 23.7.1fixed in 23.q32023-11-14
CVE-2021-46748 [MEDIUM] CWE-119 CVE-2021-46748: Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memor
Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.
nvd
CVE-2020-12960P4MEDIUMCVSS 5.5fixed in 21.4.12021-11-15
CVE-2020-12960 [MEDIUM] CWE-20 CVE-2020-12960: AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuf
AMD Graphics Driver for Windows 10, amdfender.sys may improperly handle input validation on InputBuffer which may result in a denial of service (DoS).
nvd
CVE-2020-12920P4MEDIUMCVSS 5.5fixed in 20.11.22021-11-15
CVE-2020-12920 [MEDIUM] CVE-2020-12920: A potential denial of service issue exists in the AMD Display driver Escape 0x130007 Call handler. A
A potential denial of service issue exists in the AMD Display driver Escape 0x130007 Call handler. An attacker with low privilege could potentially induce a Windows BugCheck.
nvd
CVE-2023-31307P4MEDIUMCVSS 4.4fixed in 23.12.1≤ 23.q42024-08-13
CVE-2023-31307 [MEDIUM] CWE-129 CVE-2023-31307: Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attack
Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.
nvd
← Previous3 / 3