unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2021-26398
Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution. CVE project by @Sn0wAlice
Create: 2023-01-11 19:13:26 +0000 UTC Push: 2023-01-11 19:13:28 +0000 UTC |
Live-Hack-CVE/CVE-2021-26355
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:13:21 +0000 UTC Push: 2023-01-11 19:13:24 +0000 UTC |
Live-Hack-CVE/CVE-2021-26328
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests. CVE project by @Sn0wAlice
Create: 2023-01-11 19:13:17 +0000 UTC Push: 2023-01-11 19:13:20 +0000 UTC |
Live-Hack-CVE/CVE-2021-26346
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:13:13 +0000 UTC Push: 2023-01-11 19:13:16 +0000 UTC |
Live-Hack-CVE/CVE-2021-26343
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure. CVE project by @Sn0wAlice
Create: 2023-01-11 19:13:08 +0000 UTC Push: 2023-01-11 19:13:11 +0000 UTC |
Live-Hack-CVE/CVE-2021-26316
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution. CVE project by @Sn0wAlice
Create: 2023-01-11 19:13:03 +0000 UTC Push: 2023-01-11 19:13:07 +0000 UTC |
Live-Hack-CVE/CVE-2023-22885
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:59 +0000 UTC Push: 2023-01-11 19:13:02 +0000 UTC |
Live-Hack-CVE/CVE-2023-20532
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:54 +0000 UTC Push: 2023-01-11 19:12:57 +0000 UTC |
Live-Hack-CVE/CVE-2023-20531
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:49 +0000 UTC Push: 2023-01-11 19:12:53 +0000 UTC |
Live-Hack-CVE/CVE-2023-20530
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:46 +0000 UTC Push: 2023-01-11 19:12:48 +0000 UTC |
Live-Hack-CVE/CVE-2023-20529
Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:42 +0000 UTC Push: 2023-01-11 19:12:44 +0000 UTC |
Live-Hack-CVE/CVE-2023-20528
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:37 +0000 UTC Push: 2023-01-11 19:12:41 +0000 UTC |
Live-Hack-CVE/CVE-2023-20527
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:33 +0000 UTC Push: 2023-01-11 19:12:36 +0000 UTC |
Live-Hack-CVE/CVE-2023-20525
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:28 +0000 UTC Push: 2023-01-11 19:12:31 +0000 UTC |
Live-Hack-CVE/CVE-2023-20523
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:23 +0000 UTC Push: 2023-01-11 19:12:26 +0000 UTC |
Live-Hack-CVE/CVE-2023-0161
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:18 +0000 UTC Push: 2023-01-11 19:12:22 +0000 UTC |
Live-Hack-CVE/CVE-2022-23814
Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:14 +0000 UTC Push: 2023-01-11 19:12:17 +0000 UTC |
Live-Hack-CVE/CVE-2022-23813
The software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest memory in a confidential compute environment. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:09 +0000 UTC Push: 2023-01-11 19:12:12 +0000 UTC |
Live-Hack-CVE/CVE-2021-46767
Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:04 +0000 UTC Push: 2023-01-11 19:12:08 +0000 UTC |
Live-Hack-CVE/CVE-2023-22952
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:00 +0000 UTC Push: 2023-01-11 19:12:03 +0000 UTC |
Previous
729
730
731
732
733
734
735
736
Next