7

CVSS4.0

CVE-2024-36355 -

Improper input validation in the SMM handler could allow an attacker with Ring0 access to write to SMRAM and modify execution flow for S3 (sleep) wake up, potentially resulting in arbitrary code execution.

๐Ÿ“… Published: Feb. 10, 2026, 7:28 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS4.0

CVE-2024-36310 -

Improper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMRAM potentially resulting in loss of confidentiality or integrity.

๐Ÿ“… Published: Feb. 10, 2026, 7:24 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.5

CVSS4.0

CVE-2025-29946 -

Insufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a loss of confidentiality and integrity in guest memory.

๐Ÿ“… Published: Feb. 10, 2026, 7:15 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

1.8

CVSS4.0

CVE-2025-0029 -

Improper handling of error condition during host-induced faults can allow a local high-privileged attack to selectively drop guest DMA writes, potentially resulting in a loss of SEV-SNP guest memory integrity

๐Ÿ“… Published: Feb. 10, 2026, 7:15 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS4.0

CVE-2025-0031 -

A use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a different socket than the migration agent potentially resulting in loss of integrity.

๐Ÿ“… Published: Feb. 10, 2026, 7:14 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4

CVSS4.0

CVE-2025-48514 -

Insufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potentially resulting in a loss of confidentiality.

๐Ÿ“… Published: Feb. 10, 2026, 7:14 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.8

CVSS4.0

CVE-2025-54514 -

Improper isolation of shared resources on a system on a chip by a malicious local attacker with high privileges could potentially lead to a partial loss of integrity.

๐Ÿ“… Published: Feb. 10, 2026, 7:13 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

1.8

CVSS4.0

CVE-2025-48509 -

Missing Checks in certain functions related to RMP initialization can allow a local admin privileged attacker to cause misidentification of I/O memory, potentially resulting in a loss of guest memory integrity

๐Ÿ“… Published: Feb. 10, 2026, 7:13 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-52534 -

Improper bound check within AMD CPU microcode can allow a malicious guest to write to host memory, potentially resulting in loss of integrity.

๐Ÿ“… Published: Feb. 10, 2026, 7:12 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.8

CVSS4.0

CVE-2025-0012 -

Improper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged attacker corrupt or partially infer SMM memory resulting in loss of integrity or confidentiality.

๐Ÿ“… Published: Feb. 10, 2026, 7:12 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 347818
Page 1563 of 34,782
ยซ previous page ยป next page
Filters