CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
20007_office_system, 27mhz_wireless_keyboard, 365_apps, 3d_builder, 3d_viewer, Access, Accessibility_insights_for_android, Accessibility_insights_for_web, Access_multilingual_user_interface_pack, Active_directory
2022-05-03
N/A
7.5 HIGH
Internet Explorer Memory Corruption Vulnerability
Insufficient bounds checking in SEV-ES may allow an attacker to corrupt Reverse Map table (RMP) memory, potentially resulting in a loss of SNP (Secure Nested Paging) memory integrity.
16h_model_00h_processor, 16h_model_0fh_processor, 16h_model_processor_firmware, A10-9600p, A10-9600p_firmware, A10-9630p, A10-9630p_firmware, A12-9700p, A12-9700p_firmware, A12-9730p
2022-05-17
N/A
7.1 HIGH
Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.
A randomly generated Initialization Vector (IV) may lead to a collision of IVs with the same key potentially resulting in information disclosure.
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.
Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.
16h_model_00h_processor, 16h_model_0fh_processor, 16h_model_processor_firmware, A10-9600p, A10-9600p_firmware, A10-9630p, A10-9630p_firmware, A12-9700p, A12-9700p_firmware, A12-9730p
2023-01-18
N/A
6.5 MEDIUM
Insufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confidentiality.
Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regions which may lead to a potential loss of integrity and availability.
16h_model_00h_processor, 16h_model_0fh_processor, 16h_model_processor_firmware, A10-9600p, A10-9600p_firmware, A10-9630p, A10-9630p_firmware, A12-9700p, A12-9700p_firmware, A12-9730p
2022-03-18
N/A
5.6 MEDIUM
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
AMD processors may speculatively re-order load instructions which can result in stale data being observed when multiple processors are operating on shared memory, resulting in potential data leakage.
