CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Insufficient input validation in SVC_ECC_PRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential loss of integrity and availability.
16h_model_00h_processor, 16h_model_0fh_processor, 16h_model_processor_firmware, A10-9600p, A10-9600p_firmware, A10-9630p, A10-9630p_firmware, A12-9700p, A12-9700p_firmware, A12-9730p
2022-08-19
N/A
5.6 MEDIUM
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may potentially leak sensitive information.
16h_model_00h_processor, 16h_model_0fh_processor, 16h_model_processor_firmware, A10-9600p, A10-9600p_firmware, A10-9630p, A10-9630p_firmware, A12-9700p, A12-9700p_firmware, A12-9730p
2022-05-16
N/A
7.8 HIGH
Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.
Insufficient input validation in SEV firmware may allow an attacker to perform out-of-bounds memory reads within the ASP boot loader, potentially leading to a denial of service.
Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.
16h_model_00h_processor, 16h_model_0fh_processor, 16h_model_processor_firmware, A10-9600p, A10-9600p_firmware, A10-9630p, A10-9630p_firmware, A12-9700p, A12-9700p_firmware, A12-9730p
2022-10-26
N/A
6.5 MEDIUM
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
Admob, Android, Android_api, Android_browser, Android_debug_bridge, Android_one, Android_sdk, Android_sdk_platform_tools, Android_sdk_tools, Android_tv
2022-04-08
N/A
9.1 CRITICAL
In Firebase PHP-JWT before 6.0.0, an algorithm-confusion issue (e.g., RS256 / HS256) exists via the kid (aka Key ID) header, when multiple types of keys are loaded in a key ring. This allows an attacker to forge tokens that validate under the incorrect key. NOTE: this provides a straightforward way to use the PHP-JWT library unsafely, but might not be considered a vulnerability in the library itself.
The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful exploitation of this vulnerability may affect the availability.
The basic framework and setting module have defects, which were introduced during the design. Successful exploitation of this vulnerability may affect system integrity.
