nvidia CVE Vulnerabilities & Metrics

Focus on nvidia vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About nvidia Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with nvidia. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total nvidia CVEs: 510
Earliest CVE date: 18 Oct 2006, 04:06 UTC
Latest CVE date: 15 Oct 2024, 06:15 UTC

Latest CVE reference: CVE-2024-0129

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 19

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -69.84%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -69.84%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical nvidia CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 3.75

Max CVSS: 10.0

Critical CVEs (≥9): 4

CVSS Range vs. Count

Range Count
0.0-3.9 233
4.0-6.9 168
7.0-8.9 117
9.0-10.0 4

CVSS Distribution Chart

Top 5 Highest CVSS nvidia CVEs

These are the five CVEs with the highest CVSS scores for nvidia, sorted by severity first and recency.

All CVEs for nvidia

CVE-2024-0129 nvidia vulnerability CVSS: 0 15 Oct 2024, 06:15 UTC

NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering.

CVE-2024-0111 nvidia vulnerability CVSS: 0 31 Aug 2024, 09:15 UTC

NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed ELF file. A successful exploit of this vulnerability may lead to a limited denial of service or data tampering.

CVE-2024-0110 nvidia vulnerability CVSS: 0 31 Aug 2024, 09:15 UTC

NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by passing in a malformed ELF file. A successful exploit of this vulnerability may lead to code execution or denial of service.

CVE-2024-0109 nvidia vulnerability CVSS: 0 31 Aug 2024, 09:15 UTC

NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malformed ELF file. A successful exploit of this vulnerability may cause an out of bounds read in the unprivileged process memory which could lead to a limited denial of service.

CVE-2024-0115 nvidia vulnerability CVSS: 0 12 Aug 2024, 13:38 UTC

NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue by a long running CV-CUDA Python process. A successful exploit of this vulnerability may lead to denial of service and data loss.

CVE-2024-0113 nvidia vulnerability CVSS: 0 12 Aug 2024, 13:38 UTC

NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.

CVE-2024-0104 nvidia vulnerability CVSS: 0 08 Aug 2024, 18:15 UTC

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.

CVE-2024-0108 nvidia vulnerability CVSS: 0 08 Aug 2024, 17:15 UTC

NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.

CVE-2024-0107 nvidia vulnerability CVSS: 0 08 Aug 2024, 17:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-0102 nvidia vulnerability CVSS: 0 08 Aug 2024, 17:15 UTC

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiving a user into reading a malformed ELF file. A successful exploit of this vulnerability might lead to denial of service.

CVE-2024-0101 nvidia vulnerability CVSS: 0 08 Aug 2024, 17:15 UTC

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch. A successful exploit of this vulnerability might lead to denial of service.

CVE-2024-0093 nvidia vulnerability CVSS: 0 13 Jun 2024, 22:15 UTC

NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure.

CVE-2024-0092 nvidia vulnerability CVSS: 0 13 Jun 2024, 22:15 UTC

NVIDIA GPU Driver for Windows and Linux contains a vulnerability where an improper check or improper handling of exception conditions might lead to denial of service.

CVE-2024-0091 nvidia vulnerability CVSS: 0 13 Jun 2024, 22:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user can cause an untrusted pointer dereference by executing a driver API. A successful exploit of this vulnerability might lead to denial of service, information disclosure, and data tampering.

CVE-2024-0090 nvidia vulnerability CVSS: 0 13 Jun 2024, 22:15 UTC

NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-0089 nvidia vulnerability CVSS: 0 13 Jun 2024, 22:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering.

CVE-2024-0086 nvidia vulnerability CVSS: 0 13 Jun 2024, 22:15 UTC

NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin.

CVE-2024-0085 nvidia vulnerability CVSS: 0 13 Jun 2024, 22:15 UTC

NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service.

CVE-2024-0084 nvidia vulnerability CVSS: 0 13 Jun 2024, 22:15 UTC

NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service.

CVE-2023-31037 nvidia vulnerability CVSS: 0 24 Jan 2024, 03:15 UTC

NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A successful exploit of this vulnerability may lead to code execution on the OS.

CVE-2023-31035 nvidia vulnerability CVSS: 0 12 Jan 2024, 19:15 UTC

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may cause an SMI callout vulnerability that could be used to execute arbitrary code at the SMM level. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, and information disclosure.

CVE-2023-31034 nvidia vulnerability CVSS: 0 12 Jan 2024, 19:15 UTC

NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.

CVE-2023-31033 nvidia vulnerability CVSS: 0 12 Jan 2024, 19:15 UTC

NVIDIA DGX A100 BMC contains a vulnerability where a user may cause a missing authentication issue for a critical function by an adjacent network . A successful exploit of this vulnerability may lead to escalation of privileges, code execution, denial of service, information disclosure, and data tampering.

CVE-2023-31032 nvidia vulnerability CVSS: 0 12 Jan 2024, 19:15 UTC

NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a dynamic variable evaluation by local access. A successful exploit of this vulnerability may lead to denial of service.

CVE-2023-31031 nvidia vulnerability CVSS: 0 12 Jan 2024, 19:15 UTC

NVIDIA DGX A100 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.

CVE-2023-31030 nvidia vulnerability CVSS: 0 12 Jan 2024, 19:15 UTC

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

CVE-2023-31029 nvidia vulnerability CVSS: 0 12 Jan 2024, 19:15 UTC

NVIDIA DGX A100 baseboard management controller (BMC) contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause a stack overflow by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

CVE-2023-31025 nvidia vulnerability CVSS: 0 12 Jan 2024, 19:15 UTC

NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to information disclosure.

CVE-2023-31024 nvidia vulnerability CVSS: 0 12 Jan 2024, 19:15 UTC

NVIDIA DGX A100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated attacker may cause stack memory corruption by sending a specially crafted network packet. A successful exploit of this vulnerability may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

CVE-2023-31027 nvidia vulnerability CVSS: 0 02 Nov 2023, 19:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability that allows Windows users with low levels of privilege to escalate privileges when an administrator is updating GPU drivers, which may lead to escalation of privileges.

CVE-2023-31026 nvidia vulnerability CVSS: 0 02 Nov 2023, 19:15 UTC

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service.

CVE-2023-31023 nvidia vulnerability CVSS: 0 02 Nov 2023, 19:15 UTC

NVIDIA Display Driver for Windows contains a vulnerability where an attacker may cause a pointer dereference of an untrusted value, which may lead to denial of service.

CVE-2023-31022 nvidia vulnerability CVSS: 0 02 Nov 2023, 19:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a NULL-pointer dereference may lead to denial of service.

CVE-2023-31021 nvidia vulnerability CVSS: 0 02 Nov 2023, 19:15 UTC

NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a malicious user in the guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

CVE-2023-31020 nvidia vulnerability CVSS: 0 02 Nov 2023, 19:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access control, which may lead to denial of service or data tampering.

CVE-2023-31019 nvidia vulnerability CVSS: 0 02 Nov 2023, 19:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in wksServicePlugin.dll, where the driver implementation does not restrict or incorrectly restricts access from the named pipe server to a connecting client, which may lead to potential impersonation to the client's secure context.

CVE-2023-31018 nvidia vulnerability CVSS: 0 02 Nov 2023, 19:15 UTC

NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.

CVE-2023-31017 nvidia vulnerability CVSS: 0 02 Nov 2023, 19:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may be able to write arbitrary data to privileged locations by using reparse points. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2023-31016 nvidia vulnerability CVSS: 0 02 Nov 2023, 19:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability where an uncontrolled search path element may allow an attacker to execute arbitrary code, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2023-44216 nvidia vulnerability CVSS: 0 27 Sep 2023, 15:19 UTC

PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.

CVE-2023-31014 nvidia vulnerability CVSS: 0 20 Sep 2023, 02:15 UTC

NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for the streamer component. A successful exploit of this vulnerability may lead to limited information disclosure, denial of service, and code execution.

CVE-2023-25525 nvidia vulnerability CVSS: 0 20 Sep 2023, 01:15 UTC

NVIDIA Cumulus Linux contains a vulnerability in forwarding where a VxLAN-encapsulated IPv6 packet received on an SVI interface with DMAC/DIPv6 set to the link-local address of the SVI interface may be incorrectly forwarded. A successful exploit may lead to information disclosure.

CVE-2023-25519 nvidia vulnerability CVSS: 0 12 Sep 2023, 02:15 UTC

NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit contains a vulnerability where a restricted host may cause an incorrect user management error. A successful exploit of this vulnerability may lead to escalation of privileges. 

CVE-2023-25524 nvidia vulnerability CVSS: 0 03 Aug 2023, 17:15 UTC

NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability may lead to information disclosure.

CVE-2023-25523 nvidia vulnerability CVSS: 0 04 Jul 2023, 00:15 UTC

NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the nvdisasm binary file, where an attacker may cause a NULL pointer dereference by providing a user with a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service.

CVE-2023-25522 nvidia vulnerability CVSS: 0 04 Jul 2023, 00:15 UTC

NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause improper input validation by providing configuration information in an unexpected format. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.

CVE-2023-25521 nvidia vulnerability CVSS: 0 04 Jul 2023, 00:15 UTC

NVIDIA DGX A100/A800 contains a vulnerability in SBIOS where an attacker may cause execution with unnecessary privileges by leveraging a weakness whereby proper input parameter validation is not performed. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.

CVE-2023-25517 nvidia vulnerability CVSS: 0 04 Jul 2023, 00:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest OS may be able to control resources for which it is not authorized, which may lead to information disclosure and data tampering.

CVE-2023-25516 nvidia vulnerability CVSS: 0 04 Jul 2023, 00:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause an integer overflow, which may lead to information disclosure and denial of service.

CVE-2023-25520 nvidia vulnerability CVSS: 0 23 Jun 2023, 18:15 UTC

NVIDIA Jetson Linux Driver Package contains a vulnerability in nvbootctrl, where a privileged local attacker can configure invalid settings, resulting in denial of service.

CVE-2023-25518 nvidia vulnerability CVSS: 0 23 Jun 2023, 18:15 UTC

NVIDIA Jetson contains a vulnerability in CBoot, where the PCIe controller is initialized without IOMMU, which may allow an attacker with physical access to the target device to read and write to arbitrary memory. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and loss of integrity.

CVE-2023-25515 nvidia vulnerability CVSS: 0 23 Jun 2023, 18:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where unexpected untrusted data is parsed, which may lead to code execution, denial of service, escalation of privileges, data tampering, or information disclosure.

CVE-2023-25514 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in cuobjdump, where an attacker may cause an out-of-bounds read by tricking a user into running cuobjdump on a malformed input file. A successful exploit of this vulnerability may lead to limited denial of service, code execution, and limited information disclosure.

CVE-2023-25513 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in cuobjdump, where an attacker may cause an out-of-bounds read by tricking a user into running cuobjdump on a malformed input file. A successful exploit of this vulnerability may lead to limited denial of service, code execution, and limited information disclosure.

CVE-2023-25512 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in cuobjdump, where an attacker may cause an out-of-bounds memory read by running cuobjdump on a malformed input file. A successful exploit of this vulnerability may lead to limited denial of service, code execution, and limited information disclosure.

CVE-2023-25511 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA CUDA Toolkit for Linux and Windows contains a vulnerability in cuobjdump, where a division-by-zero error may enable a user to cause a crash, which may lead to a limited denial of service.

CVE-2023-25510 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA CUDA Toolkit SDK for Linux and Windows contains a NULL pointer dereference in cuobjdump, where a local user running the tool against a malformed binary may cause a limited denial of service.

CVE-2023-0206 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the NVME SMM API. A successful exploit of this vulnerability may lead to denial of service, escalation of privileges, and information disclosure.

CVE-2023-0205 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service.

CVE-2023-0204 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can cause improper handling of exceptional conditions, which may lead to denial of service.

CVE-2023-0203 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can exploit insufficient granularity of access control, which may lead to denial of service.

CVE-2023-0202 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA DGX A100 SBIOS contains a vulnerability where an attacker may modify arbitrary memory of SMRAM by exploiting the GenericSio and LegacySmmSredir SMM APIs. A successful exploit of this vulnerability may lead to denial of service, escalation of privileges, and information disclosure.

CVE-2023-0199 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds write can lead to denial of service and data tampering.

CVE-2023-0190 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a NULL pointer dereference may lead to denial of service.

CVE-2023-0184 nvidia vulnerability CVSS: 0 22 Apr 2023, 03:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler which may lead to denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2023-0198 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where improper restriction of operations within the bounds of a memory buffer can lead to denial of service, information disclosure, and data tampering.

CVE-2023-0197 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

CVE-2023-0195 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer driver nvlddmkm.sys, where an can cause CWE-1284, which may lead to hypothetical Information leak of unimportant data such as local variable data of the driver

CVE-2023-0194 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer driver, where an invalid display configuration may lead to denial of service.

CVE-2023-0192 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer handler, where improper privilege management can lead to escalation of privileges and information disclosure.

CVE-2023-0191 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds access may lead to denial of service or data tampering.

CVE-2023-0189 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2023-0188 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged user can cause improper restriction of operations within the bounds of a memory buffer cause an out-of-bounds read, which may lead to denial of service.

CVE-2023-0187 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read can lead to denial of service.

CVE-2023-0186 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service and data tampering.

CVE-2023-0185 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign conversion issuescasting an unsigned primitive to signed may lead to denial of service or information disclosure.

CVE-2023-0183 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an out-of-bounds write can lead to denial of service and data tampering.

CVE-2023-0182 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service, information disclosure, and data tampering.

CVE-2023-0181 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory permissions are not correctly checked, which may lead to denial of service and data tampering.

CVE-2023-0180 nvidia vulnerability CVSS: 0 01 Apr 2023, 05:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in a kernel mode layer handler, which may lead to denial of service or information disclosure.

CVE-2023-0208 nvidia vulnerability CVSS: 0 01 Apr 2023, 04:15 UTC

NVIDIA DCGM for Linux contains a vulnerability in HostEngine (server component) where a user may cause a heap-based buffer overflow through the bound socket. A successful exploit of this vulnerability may lead to denial of service and data tampering.

CVE-2023-0193 nvidia vulnerability CVSS: 0 10 Mar 2023, 21:15 UTC

NVIDIA CUDA Toolkit SDK contains a vulnerability in cuobjdump, where a local user running the tool against a malicious binary may cause an out-of-bounds read, which may result in a limited denial of service and limited information disclosure.

CVE-2023-0196 nvidia vulnerability CVSS: 0 02 Mar 2023, 02:15 UTC

NVIDIA CUDA Toolkit SDK contains a bug in cuobjdump, where a local user running the tool against an ill-formed binary may cause a null- pointer dereference, which may result in a limited denial of service.

CVE-2022-42292 nvidia vulnerability CVSS: 0 12 Feb 2023, 04:15 UTC

NVIDIA GeForce Experience contains a vulnerability in the NVContainer component, where a user without administrator privileges can create a symbolic link to a file that requires elevated privileges to write to or modify, which may lead to denial of service, escalation of privilege or limited data tampering.

CVE-2022-42291 nvidia vulnerability CVSS: 0 07 Feb 2023, 03:15 UTC

NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering. An attacker does not have explicit control over the exploitation of this vulnerability, which requires the user to explicitly launch the installer from the compromised directory.

CVE-2022-31611 nvidia vulnerability CVSS: 0 07 Feb 2023, 03:15 UTC

NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an attacker with user level privileges may cause the installer to load an arbitrary DLL when the installer is launched. A successful exploit of this vulnerability could lead to escalation of privileges and code execution.

CVE-2022-42268 nvidia vulnerability CVSS: 0 13 Jan 2023, 06:15 UTC

Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to customize all aspects of a scene. If a user opens a USD file that contains embedded Python code in one of these applications, the embedded Python code automatically runs with the privileges of the user who opened the file. As a result, an unprivileged remote attacker could craft a USD file containing malicious Python code and persuade a local user to open the file, which may lead to information disclosure, data tampering, and denial of service.

CVE-2022-42290 nvidia vulnerability CVSS: 0 13 Jan 2023, 04:15 UTC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

CVE-2022-42289 nvidia vulnerability CVSS: 0 13 Jan 2023, 04:15 UTC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

CVE-2022-42288 nvidia vulnerability CVSS: 0 13 Jan 2023, 04:15 UTC

NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use certain oracles to guess a valid BMC username, which may lead to an information disclosure.

CVE-2022-42281 nvidia vulnerability CVSS: 0 13 Jan 2023, 02:15 UTC

NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure.

CVE-2022-42279 nvidia vulnerability CVSS: 0 13 Jan 2023, 02:15 UTC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

CVE-2022-42276 nvidia vulnerability CVSS: 0 13 Jan 2023, 02:15 UTC

NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

CVE-2022-42273 nvidia vulnerability CVSS: 0 12 Jan 2023, 23:15 UTC

NVIDIA BMC contains a vulnerability in libwebsocket, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

CVE-2022-42272 nvidia vulnerability CVSS: 0 12 Jan 2023, 23:15 UTC

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow, which may lead to code execution, denial of service or escalation of privileges.

CVE-2022-42271 nvidia vulnerability CVSS: 0 11 Jan 2023, 06:15 UTC

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution

CVE-2022-42270 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-based buffer overflow in kernel code, which may lead to escalation of privileges, compromised integrity and confidentiality, and denial of service.

CVE-2022-42269 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged local attacker to cause information disclosure and compromise integrity. The scope of the impact can extend to other components.

CVE-2022-42267 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2022-42266 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can cause exposure of sensitive information to an actor that is not explicitly authorized to have access to that information, which may lead to limited information disclosure.

CVE-2022-42265 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure or data tampering.

CVE-2022-42264 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause the use of an out-of-range pointer offset, which may lead to data tampering, data loss, information disclosure, or denial of service.

CVE-2022-42263 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an Integer overflow may lead to denial of service or information disclosure.

CVE-2022-42262 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.

CVE-2022-42261 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.

CVE-2022-42260 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA vGPU Display Driver for Linux guest contains a vulnerability in a D-Bus configuration file, where an unauthorized user in the guest VM can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2022-42259 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service.

CVE-2022-42258 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service, data tampering, or information disclosure.

CVE-2022-42257 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to information disclosure, data tampering or denial of service.

CVE-2022-42256 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow in index validation may lead to denial of service, information disclosure, or data tampering.

CVE-2022-42255 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering.

CVE-2022-42254 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, data tampering, or information disclosure.

CVE-2022-34684 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an off-by-one error may lead to data tampering or information disclosure.

CVE-2022-34683 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a null-pointer dereference occurs, which may lead to denial of service.

CVE-2022-34682 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a null-pointer dereference, which may lead to denial of service.

CVE-2022-34681 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler, where improper input validation of a display-related data structure may lead to denial of service.

CVE-2022-34680 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service.

CVE-2022-34679 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unhandled return value can lead to a null-pointer dereference, which may lead to denial of service.

CVE-2022-34678 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause a null-pointer dereference, which may lead to denial of service.

CVE-2022-34677 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause an integer to be truncated, which may lead to denial of service or data tampering.

CVE-2022-34676 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read may lead to denial of service, information disclosure, or data tampering.

CVE-2022-34675 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA Display Driver for Linux contains a vulnerability in the Virtual GPU Manager, where it does not check the return value from a null-pointer dereference, which may lead to denial of service.

CVE-2022-34674 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than were requested, which may lead to undefined behavior or an information leak.

CVE-2022-34673 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering.

CVE-2022-34672 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA Control Panel for Windows contains a vulnerability where an unauthorized user or an unprivileged regular user can compromise the security of the software by gaining privileges, reading sensitive information, or executing commands.

CVE-2022-34671 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user-mode layer, where an unprivileged user can cause an out-of-bounds write, which may lead to code execution, information disclosure, and denial of service.

CVE-2022-34670 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged regular user can cause truncation errors when casting a primitive to a primitive of smaller size causes data to be lost in the conversion, which may lead to denial of service or information disclosure.

CVE-2022-34669 nvidia vulnerability CVSS: 0 30 Dec 2022, 23:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2022-34667 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA CUDA Toolkit SDK contains a stack-based buffer overflow vulnerability in cuobjdump, where an unprivileged remote attacker could exploit this buffer overflow condition by persuading a local user to download a specially crafted corrupted file and execute cuobjdump against it locally, which may lead to a limited denial of service and some loss of data integrity for the local user.

CVE-2022-34665 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service.

CVE-2022-31617 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabilities can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2022-31616 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to denial of service, or information disclosure.

CVE-2022-31615 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service.

CVE-2022-31613 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where any local user can cause a null-pointer dereference, which may lead to a kernel panic.

CVE-2022-31612 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to a system crash or a leak of internal kernel information.

CVE-2022-31610 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabilities can cause an out-of-bounds write, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2022-31608 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in an optional D-Bus configuration file, where a local user with basic capabilities can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2022-31607 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where a local user with basic capabilities can cause improper input validation, which may lead to denial of service, escalation of privileges, data tampering, and limited information disclosure.

CVE-2022-31606 nvidia vulnerability CVSS: 0 19 Nov 2022, 00:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a failure to properly validate data might allow an attacker with basic user capabilities to cause an out-of-bounds access in kernel mode, which could lead to denial of service, information disclosure, escalation of privileges, or data tampering.

CVE-2022-34666 nvidia vulnerability CVSS: 0 10 Nov 2022, 16:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service.

CVE-2022-28199 nvidia vulnerability CVSS: 0 01 Sep 2022, 17:15 UTC

NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.

CVE-2022-34668 nvidia vulnerability CVSS: 0 29 Aug 2022, 03:15 UTC

NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

CVE-2022-31618 nvidia vulnerability CVSS: 0 05 Aug 2022, 21:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a null pointer, which may lead to denial of service.

CVE-2022-31614 nvidia vulnerability CVSS: 0 05 Aug 2022, 21:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may exploit this vulnerability with other vulnerabilities to cause denial of service, code execution, and information disclosure.

CVE-2022-31609 nvidia vulnerability CVSS: 0 05 Aug 2022, 21:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and confidentiality, denial of service, or information disclosure.

CVE-2022-31603 nvidia vulnerability CVSS: 4.4 04 Jul 2022, 18:15 UTC

NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with high privileges and preconditioned IpSecDxe global data can exploit improper validation of an array index to cause code execution, which may lead to denial of service, data integrity impact, and information disclosure.

CVE-2022-31602 nvidia vulnerability CVSS: 4.4 04 Jul 2022, 18:15 UTC

NVIDIA DGX A100 contains a vulnerability in SBIOS in the IpSecDxe, where a user with elevated privileges and a preconditioned heap can exploit an out-of-bounds write vulnerability, which may lead to code execution, denial of service, data integrity impact, and information disclosure.

CVE-2022-31601 nvidia vulnerability CVSS: 4.6 04 Jul 2022, 18:15 UTC

NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmbiosPei, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure.

CVE-2022-31600 nvidia vulnerability CVSS: 4.6 04 Jul 2022, 18:15 UTC

NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmmCore, where a user with high privileges can chain another vulnerability to this vulnerability, causing an integer overflow, possibly leading to code execution, escalation of privileges, denial of service, compromised integrity, and information disclosure. The scope of impact can extend to other components.

CVE-2022-31599 nvidia vulnerability CVSS: 4.6 04 Jul 2022, 18:15 UTC

NVIDIA DGX A100 contains a vulnerability in SBIOS in the Ofbd, where a local user with elevated privileges can cause access to an uninitialized pointer, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

CVE-2022-28200 nvidia vulnerability CVSS: 4.6 02 Jul 2022, 01:15 UTC

NVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can read and write beyond intended bounds in SMRAM, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

CVE-2022-31605 nvidia vulnerability CVSS: 7.5 01 Jul 2022, 18:15 UTC

NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.safe_load(). The deserialization of Untrusted Data, may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

CVE-2022-31604 nvidia vulnerability CVSS: 7.5 01 Jul 2022, 18:15 UTC

NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pickle and no safe deserialization. The deserialization of Untrusted Data may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

CVE-2022-28192 nvidia vulnerability CVSS: 1.9 17 May 2022, 20:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.

CVE-2022-28191 nvidia vulnerability CVSS: 4.9 17 May 2022, 20:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service.

CVE-2022-28190 nvidia vulnerability CVSS: 2.1 17 May 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where improper input validation can cause denial of service.

CVE-2022-28189 nvidia vulnerability CVSS: 2.1 17 May 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a NULL pointer dereference may lead to a system crash.

CVE-2022-28188 nvidia vulnerability CVSS: 4.9 17 May 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service.

CVE-2022-28187 nvidia vulnerability CVSS: 4.9 17 May 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where the memory management software does not release a resource after its effective lifetime has ended, which may lead to denial of service.

CVE-2022-28186 nvidia vulnerability CVSS: 3.6 17 May 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service or data tampering.

CVE-2022-28185 nvidia vulnerability CVSS: 3.6 17 May 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to denial of service and data tampering.

CVE-2022-28184 nvidia vulnerability CVSS: 4.6 17 May 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering.

CVE-2022-28183 nvidia vulnerability CVSS: 3.6 17 May 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause an out-of-bounds read, which may lead to denial of service and information disclosure.

CVE-2022-28182 nvidia vulnerability CVSS: 6.8 17 May 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where an unauthorized attacker on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution to cause denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.

CVE-2022-28181 nvidia vulnerability CVSS: 6.9 17 May 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.

CVE-2022-28198 nvidia vulnerability CVSS: 4.6 29 Apr 2022, 21:15 UTC

NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physical access to the system can cause arbitrary code execution which can impact confidentiality, integrity, and availability.

CVE-2022-28197 nvidia vulnerability CVSS: 4.4 27 Apr 2022, 18:15 UTC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validation of untrusted data may allow a highly privileged local attacker to cause an integer overflow. This difficult-to-exploit vulnerability may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity. The scope of impact can extend to other components.

CVE-2022-28196 nvidia vulnerability CVSS: 3.6 27 Apr 2022, 18:15 UTC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, limited loss of Integrity, and limited denial of service. The scope of impact can extend to other components.

CVE-2022-28195 nvidia vulnerability CVSS: 4.6 27 Apr 2022, 18:15 UTC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_read_file function, where insufficient validation of untrusted data may allow a highly privileged local attacker to cause a integer overflow, which may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity. The scope of impact can extend to other components.

CVE-2022-28194 nvidia vulnerability CVSS: 4.4 27 Apr 2022, 18:15 UTC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service, and some impact to confidentiality.

CVE-2022-28193 nvidia vulnerability CVSS: 4.6 27 Apr 2022, 18:15 UTC

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, loss of integrity, limited denial of service, and some impact to confidentiality.

CVE-2022-21821 nvidia vulnerability CVSS: 6.8 29 Mar 2022, 20:15 UTC

NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an attack may lead to remote code execution that causes complete denial of service and an impact on data confidentiality and integrity.

CVE-2022-21820 nvidia vulnerability CVSS: 6.5 24 Mar 2022, 17:15 UTC

NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data confidentiality and integrity.

CVE-2022-21822 nvidia vulnerability CVSS: 7.8 17 Mar 2022, 21:15 UTC

NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable.

CVE-2022-21819 nvidia vulnerability CVSS: 4.6 11 Mar 2022, 14:15 UTC

NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physical access to the board direct read/write access to the entire system address space through the PCI bus. Such an attack could result in denial of service, code execution, escalation of privileges, and impact to data integrity and confidentiality. The scope impact may extend to other components.

CVE-2022-21816 nvidia vulnerability CVSS: 4.9 07 Feb 2022, 20:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service.

CVE-2022-21815 nvidia vulnerability CVSS: 4.9 07 Feb 2022, 20:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash.

CVE-2022-21814 nvidia vulnerability CVSS: 3.6 07 Feb 2022, 20:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service.

CVE-2022-21813 nvidia vulnerability CVSS: 3.6 07 Feb 2022, 20:15 UTC

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service.

CVE-2022-21817 nvidia vulnerability CVSS: 5.8 02 Feb 2022, 13:15 UTC

NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of privileges, and impact to confidentiality and integrity.

CVE-2021-34406 nvidia vulnerability CVSS: 4.7 18 Jan 2022, 18:15 UTC

NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointer dereference, which may lead to a system reboot.

CVE-2021-34405 nvidia vulnerability CVSS: 4.9 18 Jan 2022, 18:15 UTC

NVIDIA Linux distributions contain a vulnerability in TrustZone’s TEE_Malloc function, where an unchecked return value causing a null pointer dereference may lead to denial of service.

CVE-2021-34404 nvidia vulnerability CVSS: 4.6 18 Jan 2022, 18:15 UTC

Android images for T210 provided by NVIDIA contain a vulnerability in BROM, where failure to limit access to AHB-DMA when BROM fails may allow an unprivileged attacker with physical access to cause denial of service or impact integrity and confidentiality beyond the security scope of BROM.

CVE-2021-34403 nvidia vulnerability CVSS: 4.6 18 Jan 2022, 18:15 UTC

NVIDIA Linux distributions contain a vulnerability in nvmap ioctl, which allows any user with a local account to exploit a use-after-free condition, leading to code privilege escalation, loss of confidentiality and integrity, or denial of service.

CVE-2021-34402 nvidia vulnerability CVSS: 4.6 18 Jan 2022, 18:15 UTC

NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service, Information disclosure, loss of Integrity, or possible escalation of privileges.

CVE-2021-34401 nvidia vulnerability CVSS: 4.6 18 Jan 2022, 18:15 UTC

NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to code execution, compromised integrity, or denial of service.

CVE-2022-22821 nvidia vulnerability CVSS: 2.1 10 Jan 2022, 14:12 UTC

NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available.

CVE-2021-23175 nvidia vulnerability CVSS: 4.4 23 Dec 2021, 16:15 UTC

NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data tampering, and denial of service, affecting other resources beyond the intended security authority of GameStream.

CVE-2021-34400 nvidia vulnerability CVSS: 2.1 20 Nov 2021, 15:15 UTC

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure.

CVE-2021-34399 nvidia vulnerability CVSS: 2.1 20 Nov 2021, 15:15 UTC

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure.

CVE-2021-23219 nvidia vulnerability CVSS: 1.9 20 Nov 2021, 15:15 UTC

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure.

CVE-2021-23217 nvidia vulnerability CVSS: 6.9 20 Nov 2021, 15:15 UTC

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to instantiate a DMA write operation only within a specific time window timed to corrupt code execution, which may impact confidentiality, integrity, or availability. The scope impact may extend to other components.

CVE-2021-23201 nvidia vulnerability CVSS: 6.9 20 Nov 2021, 15:15 UTC

NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevated privileges to generate valid microcode by identifying, exploiting, and loading vulnerable microcode. Such an attack could lead to information disclosure, data corruption, or denial of service of the device. The scope may extend to other components.

CVE-2021-1125 nvidia vulnerability CVSS: 4.9 20 Nov 2021, 15:15 UTC

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data.

CVE-2021-1105 nvidia vulnerability CVSS: 2.1 20 Nov 2021, 15:15 UTC

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure.

CVE-2021-1088 nvidia vulnerability CVSS: 2.1 20 Nov 2021, 15:15 UTC

NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure.

CVE-2021-1123 nvidia vulnerability CVSS: 2.1 29 Oct 2021, 20:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can deadlock, which may lead to denial of service.

CVE-2021-1122 nvidia vulnerability CVSS: 2.1 29 Oct 2021, 20:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service.

CVE-2021-1121 nvidia vulnerability CVSS: 2.1 29 Oct 2021, 20:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel driver, where a vGPU can cause resource starvation among other vGPUs hosted on the same GPU, which may lead to denial of service.

CVE-2021-1120 nvidia vulnerability CVSS: 4.6 29 Oct 2021, 20:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. The guest OS or attacker has no ability to push content to the plugin through this vulnerability, which may lead to information disclosure, data tampering, unauthorized code execution, and denial of service.

CVE-2021-1119 nvidia vulnerability CVSS: 3.6 29 Oct 2021, 20:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead to denial of service. This flaw may result in a write-what-where condition, allowing an attacker to execute arbitrary code impacting integrity and availability.

CVE-2021-1118 nvidia vulnerability CVSS: 4.6 29 Oct 2021, 20:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to execute privileged operations by the guest OS, which may lead to information disclosure, data tampering, escalation of privileges, and denial of service

CVE-2021-1117 nvidia vulnerability CVSS: 1.9 27 Oct 2021, 21:15 UTC

Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an attacker through specific configuration and with local unprivileged system access may cause improper input validation, which may lead to denial of service.

CVE-2021-1116 nvidia vulnerability CVSS: 2.1 27 Oct 2021, 21:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a system crash.

CVE-2021-1115 nvidia vulnerability CVSS: 2.1 27 Oct 2021, 21:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs, where an attacker with local unprivileged system access may cause a NULL pointer dereference, which may lead to denial of service in a component beyond the vulnerable component.

CVE-2021-34398 nvidia vulnerability CVSS: 7.2 13 Aug 2021, 16:15 UTC

NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead to privilege escalation, total loss of confidentiality and integrity, and complete denial of service.

CVE-2021-1114 nvidia vulnerability CVSS: 4.9 11 Aug 2021, 22:15 UTC

NVIDIA Linux kernel distributions contain a vulnerability in the kernel crypto node, where use after free may lead to complete denial of service.

CVE-2021-1113 nvidia vulnerability CVSS: 5.4 11 Aug 2021, 22:15 UTC

NVIDIA camera firmware contains a difficult to exploit vulnerability where a highly privileged attacker can cause unauthorized modification to camera resources, which may result in complete denial of service and partial loss of data integrity for all clients.

CVE-2021-1112 nvidia vulnerability CVSS: 4.9 11 Aug 2021, 22:15 UTC

NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where a null pointer dereference may lead to complete denial of service.

CVE-2021-1111 nvidia vulnerability CVSS: 4.6 11 Aug 2021, 22:15 UTC

Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to buffer overflow, resulting in limited information disclosure, limited data integrity, and denial of service across all components.

CVE-2021-1110 nvidia vulnerability CVSS: 6.6 11 Aug 2021, 22:15 UTC

NVIDIA Linux kernel distributions on Jetson Xavier contain a vulnerability in camera firmware where a user can change input data after validation, which may lead to complete denial of service and serious data corruption of all kernel components.

CVE-2021-1109 nvidia vulnerability CVSS: 3.3 11 Aug 2021, 22:15 UTC

NVIDIA camera firmware contains a multistep, timing-related vulnerability where an unauthorized modification by camera resources may result in loss of data integrity or denial of service across several streams.

CVE-2021-1108 nvidia vulnerability CVSS: 4.6 11 Aug 2021, 22:15 UTC

NVIDIA Linux kernel distributions contain a vulnerability in FuSa Capture (VI/ISP), where integer underflow due to lack of input validation may lead to complete denial of service, partial integrity, and serious confidentiality loss for all processes in the system.

CVE-2021-1107 nvidia vulnerability CVSS: 4.6 11 Aug 2021, 22:15 UTC

NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVMAP_IOC_WRITE* paths, where improper access controls may lead to code execution, complete denial of service, and seriously compromised integrity of all system components.

CVE-2021-1106 nvidia vulnerability CVSS: 4.6 11 Aug 2021, 22:15 UTC

NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where writes may be allowed to read-only buffers, which may result in escalation of privileges, complete denial of service, unconstrained information disclosure, and serious data tampering of all processes on the system.

CVE-2021-1096 nvidia vulnerability CVSS: 4.9 22 Jul 2021, 05:15 UTC

NVIDIA Windows GPU Display Driver for Windows contains a vulnerability in the NVIDIA kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where dereferencing a NULL pointer may lead to a system crash.

CVE-2021-1095 nvidia vulnerability CVSS: 2.1 22 Jul 2021, 05:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.

CVE-2021-1094 nvidia vulnerability CVSS: 3.6 22 Jul 2021, 05:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.

CVE-2021-1093 nvidia vulnerability CVSS: 4.9 22 Jul 2021, 05:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may lead to denial of service or system crash.

CVE-2021-1092 nvidia vulnerability CVSS: 3.6 22 Jul 2021, 05:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overwrite privileged files, resulting in potential denial of service or data loss.

CVE-2021-1091 nvidia vulnerability CVSS: 3.6 22 Jul 2021, 05:15 UTC

NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overwrite a file that requires elevated privilege to modify, which could lead to data loss or denial of service.

CVE-2021-1090 nvidia vulnerability CVSS: 3.6 22 Jul 2021, 05:15 UTC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer, which may lead to data tampering or denial of service.

CVE-2021-1089 nvidia vulnerability CVSS: 4.6 22 Jul 2021, 05:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in nvidia-smi where an uncontrolled DLL loading path may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

CVE-2021-1103 nvidia vulnerability CVSS: 2.1 21 Jul 2021, 03:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-1102 nvidia vulnerability CVSS: 2.1 21 Jul 2021, 03:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can lead to floating point exceptions, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-1101 nvidia vulnerability CVSS: 2.1 21 Jul 2021, 03:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-1100 nvidia vulnerability CVSS: 2.1 21 Jul 2021, 03:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel mode driver (nvidia.ko), in which a pointer to a user-space buffer is not validated before it is dereferenced, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-1099 nvidia vulnerability CVSS: 4.6 21 Jul 2021, 03:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) that could allow an attacker to cause stack-based buffer overflow and put a customized ROP gadget on the stack. Such an attack may lead to information disclosure, data tampering, or denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-1098 nvidia vulnerability CVSS: 4.6 21 Jul 2021, 03:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it doesn't release some resources during driver unload requests from guests. This flaw allows a malicious guest to perform operations by reusing those resources, which may lead to information disclosure, data tampering, or denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-1097 nvidia vulnerability CVSS: 4.6 21 Jul 2021, 03:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it improperly validates the length field in a request from a guest. This flaw allows a malicious guest to send a length field that is inconsistent with the actual length of the input, which may lead to information disclosure, data tampering, or denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

CVE-2021-34385 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calculation of a length could lead to a heap overflow.

CVE-2021-34384 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow could cause memory corruption, which might lead to denial of service or code execution.

CVE-2021-34383 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might lead to denial of service or escalation of privileges.

CVE-2021-34382 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel’s tz_map_shared_mem function where an integer overflow on the size parameter causes the request buffer and the logging buffer to overflow, allowing writes to arbitrary addresses within the kernel.

CVE-2021-34381 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow on the size parameter of the tz_map_shared_mem function, which might lead to denial of service, information disclosure, or data tampering.

CVE-2021-34380 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and information disclosure during secure boot.

CVE-2021-34379 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an I/O buffer parameter is not checked, which might lead to memory corruption.

CVE-2021-34378 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 11 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to information disclosure, denial of service, or escalation of privileges.

CVE-2021-34377 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 9 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to escalation of privileges, information disclosure, and denial of service.

CVE-2021-34376 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 5 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to denial of service, escalation of privileges, and information disclosure.

CVE-2021-34375 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Trusty contains a vulnerability in all trusted applications (TAs) where the stack cookie was not randomized, which might result in stack-based buffer overflow, leading to denial of service, escalation of privileges, and information disclosure.

CVE-2021-34374 nvidia vulnerability CVSS: 4.6 30 Jun 2021, 11:15 UTC

Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerability can cause memory corruption, which may lead to information disclosure, escalation of privileges, and denial of service.

CVE-2021-34373 nvidia vulnerability CVSS: 3.6 30 Jun 2021, 11:15 UTC

Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could cause heap overflows, which might lead to information disclosure and denial of service.

CVE-2021-1073 nvidia vulnerability CVSS: 5.1 25 Jun 2021, 20:15 UTC

NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to log in by using a browser, while, at the same time, any other web page is loaded in other tabs of the same browser. In this situation, the web page can get access to the token of the user login session, leading to the possibility that the user’s account is compromised. This may lead to the targeted user’s data being accessed, altered, or lost.

CVE-2021-34397 nvidia vulnerability CVSS: 2.1 22 Jun 2021, 22:15 UTC

Bootloader contains a vulnerability in NVIDIA MB2, which may cause free-the-wrong-heap, which may lead to limited denial of service.

CVE-2021-34396 nvidia vulnerability CVSS: 2.1 22 Jun 2021, 22:15 UTC

Bootloader contains a vulnerability in access permission settings where unauthorized software may be able to overwrite NVIDIA MB2 code, which would result in limited denial of service.

CVE-2021-34395 nvidia vulnerability CVSS: 4.6 22 Jun 2021, 22:15 UTC

Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure, a low risk of modifcations to data, and limited denial of service.

CVE-2021-34394 nvidia vulnerability CVSS: 4.6 22 Jun 2021, 22:15 UTC

Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker to use the malicious CA that is run by the user to cause the buffer overflow, which may lead to information disclosure and data modification.

CVE-2021-34393 nvidia vulnerability CVSS: 2.1 22 Jun 2021, 22:15 UTC

Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.

CVE-2021-34392 nvidia vulnerability CVSS: 2.1 22 Jun 2021, 22:15 UTC

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the tz_map_shared_mem function can bypass boundary checks, which might lead to denial of service.

CVE-2021-34391 nvidia vulnerability CVSS: 4.9 22 Jun 2021, 22:15 UTC

Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow through a specific SMC call that is triggered by the user, which may lead to denial of service.

CVE-2021-34390 nvidia vulnerability CVSS: 2.1 22 Jun 2021, 22:15 UTC

Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow through a specific SMC call that is triggered by the user, which may lead to denial of service.

CVE-2021-34372 nvidia vulnerability CVSS: 4.6 22 Jun 2021, 22:15 UTC

Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol message parsing code where an integer overflow in a malloc() size calculation leads to a buffer overflow on the heap, which might result in information disclosure, escalation of privileges, and denial of service.

CVE-2021-34389 nvidia vulnerability CVSS: 1.9 21 Jun 2021, 22:15 UTC

Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorrect bounds check can allow a local user through a malicious client to access memory from the heap in the TrustZone, which may lead to information disclosure.

CVE-2021-34388 nvidia vulnerability CVSS: 4.6 21 Jun 2021, 22:15 UTC

Bootloader contains a vulnerability in NVIDIA TegraBoot where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.

CVE-2021-34387 nvidia vulnerability CVSS: 7.2 21 Jun 2021, 22:15 UTC

The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and data that is otherwise mapped read only.

CVE-2021-34386 nvidia vulnerability CVSS: 4.6 21 Jun 2021, 22:15 UTC

Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calloc size calculation can cause the multiplication of count and size can overflow, which might lead to heap overflows.

CVE-2021-1087 nvidia vulnerability CVSS: 2.1 29 Apr 2021, 19:15 UTC

NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), which could allow an attacker to retrieve information that could lead to a Address Space Layout Randomization (ASLR) bypass. This affects vGPU version 12.x (prior to 12.2), version 11.x (prior to 11.4) and version 8.x (prior to 8.7).

CVE-2021-1086 nvidia vulnerability CVSS: 3.6 29 Apr 2021, 19:15 UTC

NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it allows guests to control unauthorized resources, which may lead to integrity and confidentiality loss or information disclosure. This affects vGPU version 12.x (prior to 12.2), version 11.x (prior to 11.4) and version 8.x (prior to 8.7).

CVE-2021-1085 nvidia vulnerability CVSS: 4.6 29 Apr 2021, 19:15 UTC

NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to write to a shared memory location and manipulate the data after the data has been validated, which may lead to denial of service and escalation of privileges and information disclosure but attacker doesn't have control over what information is obtained. This affects vGPU version 12.x (prior to 12.2), version 11.x (prior to 11.4) and version 8.x (prior to 8.7).

CVE-2021-1084 nvidia vulnerability CVSS: 4.6 29 Apr 2021, 19:15 UTC

NVIDIA vGPU driver contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data or denial of service. This affects vGPU version 12.x (prior to 12.2) and version 11.x (prior to 11.4).

CVE-2021-1083 nvidia vulnerability CVSS: 4.6 29 Apr 2021, 19:15 UTC

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of service. This affects vGPU version 12.x (prior to 12.2) and version 11.x (prior to 11.4).

CVE-2021-1082 nvidia vulnerability CVSS: 4.6 29 Apr 2021, 19:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of service. vGPU version 12.x (prior to 12.2), version 11.x (prior to 11.4) and version 8.x (prior to 8.7)

CVE-2021-1081 nvidia vulnerability CVSS: 4.6 29 Apr 2021, 19:15 UTC

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data, or denial of service. This affects vGPU version 12.x (prior to 12.2), version 11.x (prior to 11.4) and version 8.x (prior 8.7).

CVE-2021-1080 nvidia vulnerability CVSS: 4.6 29 Apr 2021, 19:15 UTC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), in which certain input data is not validated, which may lead to information disclosure, tampering of data, or denial of service. This affects vGPU version 12.x (prior to 12.2), version 11.x (prior to 11.4) and version 8.x (prior 8.7).

CVE-2021-1078 nvidia vulnerability CVSS: 4.9 21 Apr 2021, 23:15 UTC

NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel driver (nvlddmkm.sys) where a NULL pointer dereference may lead to system crash.

CVE-2021-1077 nvidia vulnerability CVSS: 2.1 21 Apr 2021, 23:15 UTC

NVIDIA GPU Display Driver for Windows and Linux, R450 and R460 driver branch, contains a vulnerability where the software uses a reference count to manage a resource that is incorrectly updated, which may lead to denial of service.

CVE-2021-1076 nvidia vulnerability CVSS: 4.6 21 Apr 2021, 23:15 UTC

NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys or nvidia.ko) where improper access control may lead to denial of service, information disclosure, or data corruption.

CVE-2021-1075 nvidia vulnerability CVSS: 5.6 21 Apr 2021, 23:15 UTC

NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the program dereferences a pointer that contains a location for memory that is no longer valid, which may lead to code execution, denial of service, or escalation of privileges. Attacker does not have any control over the information and may conduct limited data modification.

CVE-2021-1074 nvidia vulnerability CVSS: 6.9 21 Apr 2021, 23:15 UTC

NVIDIA GPU Display Driver for Windows installer contains a vulnerability where an attacker with local unprivileged system access may be able to replace an application resource with malicious files. This attack requires a user with system administration rights to execute the installer and requires the attacker to replace the files in a very short time window between file integrity validation and execution. Such an attack may lead to code execution, escalation of privileges, denial of service, and information disclosure.

CVE-2021-1079 nvidia vulnerability CVSS: 3.6 20 Apr 2021, 16:15 UTC

NVIDIA GeForce Experience, all versions prior to 3.22, contains a vulnerability in GameStream plugins where log files are created using NT/System level permissions, which may lead to code execution, denial of service, or local privilege escalation. The attacker does not have control over the consequence of a modification nor would they be able to leak information as a direct result of the overwrite.

CVE-2021-1072 nvidia vulnerability CVSS: 3.6 05 Feb 2021, 20:15 UTC

NVIDIA GeForce Experience, all versions prior to 3.21, contains a vulnerability in GameStream (rxdiag.dll) where an arbitrary file deletion due to improper handling of log files may lead to denial of service.

CVE-2021-1071 nvidia vulnerability CVSS: 2.1 26 Jan 2021, 22:15 UTC

NVIDIA Tegra kernel in Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, all L4T versions prior to r32.5, contains a vulnerability in the INA3221 driver in which improper access control may lead to unauthorized users gaining access to system power usage data, which may lead to information disclosure.

CVE-2021-1070 nvidia vulnerability CVSS: 3.6 26 Jan 2021, 22:15 UTC

NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, L4T versions prior to 32.5, contains a vulnerability in the apply_binaries.sh script used to install NVIDIA components into the root file system image, in which improper access control is applied, which may lead to an unprivileged user being able to modify system device tree files, leading to denial of service.

CVE-2021-1069 nvidia vulnerability CVSS: 3.6 20 Jan 2021, 23:15 UTC

NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the NVHost function, which may lead to abnormal reboot due to a null pointer reference, causing data loss.

CVE-2021-1068 nvidia vulnerability CVSS: 4.6 20 Jan 2021, 23:15 UTC

NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the NVDEC component, in which an attacker can read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service or escalation of privileges.

CVE-2021-1067 nvidia vulnerability CVSS: 4.6 20 Jan 2021, 23:15 UTC

NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the implementation of the RPMB command status, in which an attacker can write to the Write Protect Configuration Block, which may lead to denial of service or escalation of privileges.

CVE-2021-1066 nvidia vulnerability CVSS: 2.1 08 Jan 2021, 15:15 UTC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to unexpected consumption of resources, which in turn may lead to denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-1065 nvidia vulnerability CVSS: 3.6 08 Jan 2021, 15:15 UTC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which input data is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-1064 nvidia vulnerability CVSS: 3.6 08 Jan 2021, 15:15 UTC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer, which may lead to information disclosure or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-1063 nvidia vulnerability CVSS: 4.6 08 Jan 2021, 15:15 UTC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input offset is not validated, which may lead to a buffer overread, which in turn may cause tampering of data, information disclosure, or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-1062 nvidia vulnerability CVSS: 3.6 08 Jan 2021, 15:15 UTC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-1061 nvidia vulnerability CVSS: 3.3 08 Jan 2021, 15:15 UTC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-1060 nvidia vulnerability CVSS: 3.6 08 Jan 2021, 15:15 UTC

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-1059 nvidia vulnerability CVSS: 4.6 08 Jan 2021, 15:15 UTC

NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input index is not validated, which may lead to integer overflow, which in turn may cause tampering of data, information disclosure, or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-1058 nvidia vulnerability CVSS: 3.6 08 Jan 2021, 15:15 UTC

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input data size is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-1057 nvidia vulnerability CVSS: 4.6 08 Jan 2021, 15:15 UTC

NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for which the guest is not authorized, which may lead to integrity and confidentiality loss, denial of service, or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVE-2021-1056 nvidia vulnerability CVSS: 3.6 08 Jan 2021, 01:15 UTC

NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.

CVE-2021-1055 nvidia vulnerability CVSS: 4.6 08 Jan 2021, 01:15 UTC

NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which improper access control may lead to denial of service and information disclosure.

CVE-2021-1054 nvidia vulnerability CVSS: 2.1 08 Jan 2021, 01:15 UTC

NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action, which may lead to denial of service.

CVE-2021-1053 nvidia vulnerability CVSS: 2.1 08 Jan 2021, 01:15 UTC

NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which improper validation of a user pointer may lead to denial of service.

CVE-2021-1052 nvidia vulnerability CVSS: 7.2 08 Jan 2021, 01:15 UTC

NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape or IOCTL in which user-mode clients can access legacy privileged APIs, which may lead to denial of service, escalation of privileges, and information disclosure.

CVE-2021-1051 nvidia vulnerability CVSS: 6.6 08 Jan 2021, 01:15 UTC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a local user can get elevated privileges to modify display configuration data, which may result in denial of service of the display.

CVE-2020-5992 nvidia vulnerability CVSS: 4.4 11 Nov 2020, 23:15 UTC

NVIDIA GeForce NOW application software on Windows, all versions prior to 2.0.25.119, contains a vulnerability in its open-source software dependency in which the OpenSSL library is vulnerable to binary planting attacks by a local user, which may lead to code execution or escalation of privileges.

CVE-2020-5991 nvidia vulnerability CVSS: 4.6 30 Oct 2020, 21:15 UTC

NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bounds read or write operation may lead to code execution, denial of service, or information disclosure.

CVE-2020-5990 nvidia vulnerability CVSS: 4.6 23 Oct 2020, 18:15 UTC

NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in the ShadowPlay component which may lead to local privilege escalation, code execution, denial of service or information disclosure.

CVE-2020-5978 nvidia vulnerability CVSS: 4.6 23 Oct 2020, 18:15 UTC

NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in its services in which a folder is created by nvcontainer.exe under normal user login with LOCAL_SYSTEM privileges which may lead to a denial of service or escalation of privileges.

CVE-2020-5977 nvidia vulnerability CVSS: 4.4 23 Oct 2020, 18:15 UTC

NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.

CVE-2020-5989 nvidia vulnerability CVSS: 2.1 02 Oct 2020, 21:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

CVE-2020-5988 nvidia vulnerability CVSS: 3.6 02 Oct 2020, 21:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which allocated memory can be freed twice, which may lead to information disclosure or denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

CVE-2020-5987 nvidia vulnerability CVSS: 4.6 02 Oct 2020, 21:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which guest-supplied parameters remain writable by the guest after the plugin has validated them, which may lead to the guest being able to pass invalid parameters to plugin handlers, which may lead to denial of service or escalation of privileges. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

CVE-2020-5986 nvidia vulnerability CVSS: 2.1 02 Oct 2020, 21:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

CVE-2020-5985 nvidia vulnerability CVSS: 3.6 02 Oct 2020, 21:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data length is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

CVE-2020-5984 nvidia vulnerability CVSS: 4.6 02 Oct 2020, 21:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin in which it may have the use-after-free vulnerability while freeing some resources, which may lead to denial of service, code execution, and information disclosure. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

CVE-2020-5983 nvidia vulnerability CVSS: 3.6 02 Oct 2020, 21:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin and the host driver kernel module, in which the potential exists to write to a memory location that is outside the intended boundary of the frame buffer memory allocated to guest operating systems, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version 11.0.

CVE-2020-5982 nvidia vulnerability CVSS: 2.1 02 Oct 2020, 19:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) scheduler, in which the software does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests, which may lead to denial of service.

CVE-2020-5981 nvidia vulnerability CVSS: 4.6 02 Oct 2020, 19:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), in which a specially crafted shader can cause an out of bounds access, which may lead to denial of service or code execution.

CVE-2020-5980 nvidia vulnerability CVSS: 4.6 02 Oct 2020, 19:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in multiple components in which a securely loaded system DLL will load its dependencies in an insecure fashion, which may lead to code execution or denial of service.

CVE-2020-5979 nvidia vulnerability CVSS: 4.6 02 Oct 2020, 19:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which a user is presented with a dialog box for input by a high-privilege process, which may lead to escalation of privileges.

CVE-2020-5976 nvidia vulnerability CVSS: 5.0 18 Sep 2020, 15:15 UTC

NVIDIA GeForce NOW, versions prior to 2.0.23 (Windows, macOS) and versions prior to 5.31 (Android, Shield TV), contains a vulnerability in the application software where the network test component transmits sensitive information insecurely, which may lead to information disclosure.

CVE-2020-5975 nvidia vulnerability CVSS: 5.0 18 Sep 2020, 15:15 UTC

NVIDIA GeForce NOW, versions prior to 2.0.23 on Windows and macOS, contains a vulnerability in the desktop application software that includes sensitive information as part of a URL, which may lead to information disclosure.

CVE-2020-5974 nvidia vulnerability CVSS: 4.6 08 Jul 2020, 23:15 UTC

NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileges.

CVE-2020-5973 nvidia vulnerability CVSS: 2.1 30 Jun 2020, 23:15 UTC

NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which there is the potential to execute privileged operations, which may lead to denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

CVE-2020-5972 nvidia vulnerability CVSS: 3.6 30 Jun 2020, 23:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which local pointer variables are not initialized and may be freed later, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

CVE-2020-5971 nvidia vulnerability CVSS: 4.6 30 Jun 2020, 23:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software reads from a buffer by using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer, which may lead to code execution, denial of service, escalation of privileges, or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

CVE-2020-5970 nvidia vulnerability CVSS: 3.6 30 Jun 2020, 23:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

CVE-2020-5969 nvidia vulnerability CVSS: 3.3 30 Jun 2020, 23:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it validates a shared resource before using it, creating a race condition which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

CVE-2020-5968 nvidia vulnerability CVSS: 4.6 30 Jun 2020, 23:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed by using an index or pointer, such as memory or files, which may lead to code execution, denial of service, escalation of privileges, or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).

CVE-2020-5967 nvidia vulnerability CVSS: 1.9 25 Jun 2020, 22:15 UTC

NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service.

CVE-2020-5966 nvidia vulnerability CVSS: 4.6 25 Jun 2020, 22:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, in which a NULL pointer is dereferenced, leading to denial of service or potential escalation of privileges.

CVE-2020-5965 nvidia vulnerability CVSS: 2.1 25 Jun 2020, 00:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the DirectX 11 user mode driver (nvwgf2um/x.dll), in which a specially crafted shader can cause an out of bounds access, leading to denial of service.

CVE-2020-5964 nvidia vulnerability CVSS: 4.6 25 Jun 2020, 00:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed. Such an attack may lead to code execution, denial of service or information disclosure.

CVE-2020-5963 nvidia vulnerability CVSS: 4.6 25 Jun 2020, 00:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.

CVE-2020-5962 nvidia vulnerability CVSS: 4.6 24 Jun 2020, 20:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component, in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.

CVE-2012-0953 nvidia vulnerability CVSS: 4.4 08 May 2020, 01:15 UTC

A race condition was discovered in the Linux drivers for Nvidia graphics which allowed an attacker to exfiltrate kernel memory to userspace. This issue was fixed in version 295.53.

CVE-2012-0952 nvidia vulnerability CVSS: 4.4 08 May 2020, 01:15 UTC

A heap buffer overflow was discovered in the device control ioctl in the Linux driver for Nvidia graphics cards, which may allow an attacker to overflow 49 bytes. This issue was fixed in version 295.53.

CVE-2020-5961 nvidia vulnerability CVSS: 2.1 12 Mar 2020, 20:15 UTC

NVIDIA vGPU graphics driver for guest OS contains a vulnerability in which an incorrect resource clean up on a failure path can impact the guest VM, leading to denial of service.

CVE-2020-5960 nvidia vulnerability CVSS: 2.1 12 Mar 2020, 20:15 UTC

NVIDIA Virtual GPU Manager contains a vulnerability in the kernel module (nvidia.ko), where a null pointer dereference may occur, which may lead to denial of service.

CVE-2020-5959 nvidia vulnerability CVSS: 2.1 12 Mar 2020, 20:15 UTC

NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin in which an input index value is incorrectly validated which may lead to denial of service.

CVE-2020-5958 nvidia vulnerability CVSS: 4.4 11 Mar 2020, 22:30 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can plant a malicious DLL file, which may lead to code execution, denial of service, or information disclosure.

CVE-2020-5957 nvidia vulnerability CVSS: 4.6 05 Mar 2020, 20:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.

CVE-2012-0951 nvidia vulnerability CVSS: 4.6 12 Feb 2020, 17:15 UTC

A Memory Corruption Vulnerability exists in NVIDIA Graphics Drivers 29549 due to an unknown function in the file proc/driver/nvidia/registry.

CVE-2019-5702 nvidia vulnerability CVSS: 4.4 24 Dec 2019, 22:15 UTC

NVIDIA GeForce Experience, all versions prior to 3.20.2, contains a vulnerability when GameStream is enabled in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.

CVE-2019-5688 nvidia vulnerability CVSS: 7.2 18 Nov 2019, 18:15 UTC

NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory and registers of other devices not managed by NVIDIA, which may lead to escalation of privileges, information disclosure, or denial of service.

CVE-2019-5695 nvidia vulnerability CVSS: 6.9 12 Nov 2019, 21:15 UTC

NVIDIA GeForce Experience (prior to 3.20.1) and Windows GPU Display Driver (all versions) contains a vulnerability in the local service provider component in which an attacker with local system and privileged access can incorrectly load Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), which may lead to denial of service or information disclosure through code execution.

CVE-2019-5701 nvidia vulnerability CVSS: 6.2 09 Nov 2019, 02:15 UTC

NVIDIA GeForce Experience, all versions prior to 3.20.0.118, contains a vulnerability when GameStream is enabled in which an attacker with local system access can load the Intel graphics driver DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), which may lead to denial of service, information disclosure, or escalation of privileges through code execution.

CVE-2019-5698 nvidia vulnerability CVSS: 2.1 09 Nov 2019, 02:15 UTC

NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin, in which an input index value is incorrectly validated, which may lead to denial of service.

CVE-2019-5697 nvidia vulnerability CVSS: 3.6 09 Nov 2019, 02:15 UTC

NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in which it may grant a guest access to memory that it does not own, which may lead to information disclosure or denial of service.

CVE-2019-5696 nvidia vulnerability CVSS: 2.1 09 Nov 2019, 02:15 UTC

NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in which the provision of an incorrectly sized buffer by a guest VM leads to GPU out-of-bound access, which may lead to a denial of service.

CVE-2019-5694 nvidia vulnerability CVSS: 4.4 09 Nov 2019, 02:15 UTC

NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), which may lead to denial of service or information disclosure through code execution. The attacker requires local system access.

CVE-2019-5693 nvidia vulnerability CVSS: 4.9 09 Nov 2019, 02:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) in which the program accesses or uses a pointer that has not been initialized, which may lead to denial of service.

CVE-2019-5692 nvidia vulnerability CVSS: 7.2 09 Nov 2019, 02:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the product uses untrusted input when calculating or using an array index, which may lead to escalation of privileges or denial of service.

CVE-2019-5691 nvidia vulnerability CVSS: 7.2 09 Nov 2019, 02:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which a NULL pointer is dereferenced, which may lead to denial of service or escalation of privileges.

CVE-2019-5690 nvidia vulnerability CVSS: 7.2 09 Nov 2019, 02:15 UTC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the size of an input buffer is not validated, which may lead to denial of service or escalation of privileges.

CVE-2019-5689 nvidia vulnerability CVSS: 4.6 09 Nov 2019, 02:15 UTC

NVIDIA GeForce Experience, all versions prior to 3.20.1, contains a vulnerability in the Downloader component in which a user with local system access can craft input that may allow malicious files to be downloaded and saved. This behavior may lead to code execution, denial of service, or information disclosure.

CVE-2019-5700 nvidia vulnerability CVSS: 7.2 09 Oct 2019, 22:15 UTC

NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra software contains a vulnerability in the bootloader, where it does not validate the fields of the boot image, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.

CVE-2019-5699 nvidia vulnerability CVSS: 7.2 09 Oct 2019, 22:15 UTC

NVIDIA Shield TV Experience prior to v8.0.1, NVIDIA Tegra bootloader contains a vulnerability where the software performs an incorrect bounds check, which may lead to buffer overflow resulting in escalation of privileges and code execution. escalation of privileges, and information disclosure, code execution, denial of service, or escalation of privileges.

CVE-2019-15788 nvidia vulnerability CVSS: 7.5 29 Aug 2019, 13:15 UTC

Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.

CVE-2019-5681 nvidia vulnerability CVSS: 7.2 13 Aug 2019, 15:15 UTC

NVIDIA Shield TV Experience prior to v8.0, contains a vulnerability in the custom NVIDIA API used in the mount system service where user data could be overridden, which may lead to code execution, denial of service, or information disclosure.

CVE-2019-5687 nvidia vulnerability CVSS: 3.6 06 Aug 2019, 20:15 UTC

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which an incorrect use of default permissions for an object exposes it to an unintended actor

CVE-2019-5686 nvidia vulnerability CVSS: 4.9 06 Aug 2019, 20:15 UTC

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software uses an API function or data structure in a way that relies on properties that are not always guaranteed to be valid, which may lead to denial of service.

CVE-2019-5685 nvidia vulnerability CVSS: 10.0 06 Aug 2019, 20:15 UTC

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access to a shader local temporary array, which may lead to denial of service or code execution.

CVE-2019-5684 nvidia vulnerability CVSS: 10.0 06 Aug 2019, 20:15 UTC

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause an out of bounds access of an input texture array, which may lead to denial of service or code execution.

CVE-2019-5683 nvidia vulnerability CVSS: 7.2 06 Aug 2019, 20:15 UTC

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the user mode video driver trace logger component. When an attacker has access to the system and creates a hard link, the software does not check for hard link attacks. This behavior may lead to code execution, denial of service, or escalation of privileges.

CVE-2019-5682 nvidia vulnerability CVSS: 7.2 06 Aug 2019, 20:15 UTC

NVIDIA Shield TV Experience prior to v8.0, contains a vulnerability in the NVIDIA Games App where it improperly exports an Activity but does not properly restrict which applications can launch the Activity, which may lead to code execution or denial of service.

CVE-2019-5679 nvidia vulnerability CVSS: 7.2 06 Aug 2019, 20:15 UTC

NVIDIA Shield TV Experience prior to v8.0, NVIDIA Tegra bootloader contains a vulnerability in nvtboot where the Trusted OS image is improperly authenticated, which may lead to code execution, denial of service, escalation of privileges, and information disclosure, code execution, denial of service, or escalation of privileges

CVE-2019-5680 nvidia vulnerability CVSS: 4.6 19 Jul 2019, 20:15 UTC

In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is loaded without the load address first being validated, which may lead to code execution, denial of service, or escalation of privileges.

CVE-2017-6261 nvidia vulnerability CVSS: 4.6 05 Jun 2019, 14:29 UTC

NVIDIA Vibrante Linux version 1.1, 2.0, and 2.2 contains a vulnerability in the user space driver in which protection mechanisms are insufficient, may lead to denial of service or information disclosure.

CVE-2019-5678 nvidia vulnerability CVSS: 4.6 31 May 2019, 22:29 UTC

NVIDIA GeForce Experience versions prior to 3.19 contains a vulnerability in the Web Helper component, in which an attacker with local system access can craft input that may not be properly validated. Such an attack may lead to code execution, denial of service or information disclosure.

CVE-2019-5677 nvidia vulnerability CVSS: 4.9 10 May 2019, 21:29 UTC

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DeviceIoControl where the software reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer, which may lead to denial of service.

CVE-2019-5676 nvidia vulnerability CVSS: 7.2 10 May 2019, 21:29 UTC

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.

CVE-2019-5675 nvidia vulnerability CVSS: 7.2 10 May 2019, 21:29 UTC

NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the product does not properly synchronize shared data, such as static variables across threads, which can lead to undefined behavior and unpredictable data changes, which may lead to denial of service, escalation of privileges, or information disclosure.

CVE-2018-6269 nvidia vulnerability CVSS: 4.6 12 Apr 2019, 17:29 UTC

NVIDIA Jetson TX2 contains a vulnerability in the kernel driver where input/output control (IOCTL) handling for user mode requests could create a non-trusted pointer dereference, which may lead to information disclosure, denial of service, escalation of privileges, or code execution. The updates apply to all versions prior to R28.3.

CVE-2018-6239 nvidia vulnerability CVSS: 2.1 12 Apr 2019, 17:29 UTC

NVIDIA Jetson TX2 contains a vulnerability by means of speculative execution where local and unprivileged code may access the contents of cached information in an unauthorized manner, which may lead to information disclosure. The updates apply to all versions prior to R28.3.

CVE-2019-5673 nvidia vulnerability CVSS: 3.6 11 Apr 2019, 17:29 UTC

NVIDIA Jetson TX2 contains a vulnerability in the kernel driver (on all versions prior to R28.3) where the ARM System Memory Management Unit (SMMU) improperly checks for a fault condition, causing transactions to be discarded, which may lead to denial of service.

CVE-2019-5672 nvidia vulnerability CVSS: 6.4 11 Apr 2019, 17:29 UTC

NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure.

CVE-2018-3979 nvidia vulnerability CVSS: 4.3 01 Apr 2019, 21:30 UTC

A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-service issues. An attacker can provide a specially crafted website to trigger this vulnerability. This vulnerability can be triggered remotely after the user visits a malformed website. No further user interaction is required. Vulnerable versions include Ubuntu 18.04 LTS (linux 4.15.0-29-generic x86_64), Nouveau Display Driver NV117 (vermagic: 4.15.0-29-generic SMP mod_unload).

CVE-2019-5674 nvidia vulnerability CVSS: 6.9 28 Mar 2019, 15:29 UTC

NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enabled. When an attacker has access to the system and creates a hard link, the software does not check for hard link attacks. This behavior may lead to code execution, denial of service, or escalation of privileges.

CVE-2019-5671 nvidia vulnerability CVSS: 4.9 27 Feb 2019, 23:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not release a resource after its effective lifetime has ended, which may lead to denial of service.

CVE-2019-5670 nvidia vulnerability CVSS: 7.2 27 Feb 2019, 23:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape in which the software uses a sequential operation to read from or write to a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer which may lead to denial of service, escalation of privileges, code execution or information disclosure.

CVE-2019-5669 nvidia vulnerability CVSS: 7.2 27 Feb 2019, 23:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape in which the software uses a sequential operation to read from or write to a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer, which may lead to denial of service or escalation of privileges.

CVE-2019-5668 nvidia vulnerability CVSS: 7.2 27 Feb 2019, 23:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiSubmitCommandVirtual in which the application dereferences a pointer that it expects to be valid, but is NULL, which may lead to denial of service or escalation of privileges.

CVE-2019-5667 nvidia vulnerability CVSS: 7.2 27 Feb 2019, 23:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiSetRootPageTable in which the application dereferences a pointer that it expects to be valid, but is NULL, which may lead to code execution, denial of service or escalation of privileges.

CVE-2019-5666 nvidia vulnerability CVSS: 7.2 27 Feb 2019, 23:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) create context command DDI DxgkDdiCreateContext in which the product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array, which may lead to denial of service or escalation of privileges.

CVE-2019-5665 nvidia vulnerability CVSS: 7.2 27 Feb 2019, 23:29 UTC

NVIDIA Windows GPU Display driver contains a vulnerability in the 3D vision component in which the stereo service software, when opening a file, does not check for hard links. This behavior may lead to code execution, denial of service or escalation of privileges.

CVE-2018-6266 nvidia vulnerability CVSS: 2.1 27 Nov 2018, 18:29 UTC

NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtain third party integration parameters, which may lead to information disclosure.

CVE-2018-6265 nvidia vulnerability CVSS: 4.6 27 Nov 2018, 18:29 UTC

NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 during application installation on Windows 7 in elevated privilege mode, where a local user who initiates a browser session may obtain escalation of privileges on the browser.

CVE-2018-6263 nvidia vulnerability CVSS: 4.6 27 Nov 2018, 18:29 UTC

NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows in which an attacker who has access to a local user account can plant a malicious dynamic link library (DLL) during application installation, which may lead to escalation of privileges.

CVE-2018-6260 nvidia vulnerability CVSS: 2.1 13 Nov 2018, 17:29 UTC

NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters. Local user access is required. This is not a network or remote attack vector.

CVE-2018-6262 nvidia vulnerability CVSS: 1.9 02 Oct 2018, 17:29 UTC

NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled where limited sensitive user information may be available to users with system access, which may lead to information disclosure.

CVE-2018-6261 nvidia vulnerability CVSS: 4.4 02 Oct 2018, 17:29 UTC

NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled which sets incorrect permissions on a file, which may to code execution, denial of service, or escalation of privileges by users with system access.

CVE-2018-6259 nvidia vulnerability CVSS: 1.9 31 Aug 2018, 20:29 UTC

NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled, an attacker has system access, and certain system features are enabled, where limited information disclosure may be possible.

CVE-2018-6258 nvidia vulnerability CVSS: 1.9 31 Aug 2018, 20:29 UTC

NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability during GameStream installation where an attacker who has system access can potentially conduct a Man-in-the-Middle (MitM) attack to obtain sensitive information.

CVE-2018-6257 nvidia vulnerability CVSS: 4.4 31 Aug 2018, 20:29 UTC

NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled where improper access control may lead to a denial of service, escalation of privileges, or both.

CVE-2018-3639 nvidia vulnerability CVSS: 2.1 22 May 2018, 12:29 UTC

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

CVE-2018-6242 nvidia vulnerability CVSS: 7.2 01 May 2018, 20:29 UTC

Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to execute unverified code.

CVE-2018-6253 nvidia vulnerability CVSS: 4.9 02 Apr 2018, 16:29 UTC

NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinite recursion leading to denial of service.

CVE-2018-6252 nvidia vulnerability CVSS: 4.9 02 Apr 2018, 16:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape where the software allows an actor access to restricted functionality that is unnecessary to production usage, and which may result in denial of service.

CVE-2018-6251 nvidia vulnerability CVSS: 7.2 02 Apr 2018, 16:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the DirectX 10 Usermode driver, where a specially crafted pixel shader can cause writing to unallocated memory, leading to denial of service or potential code execution.

CVE-2018-6250 nvidia vulnerability CVSS: 7.2 02 Apr 2018, 16:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a NULL pointer dereference occurs which may lead to denial of service or possible escalation of privileges.

CVE-2018-6249 nvidia vulnerability CVSS: 7.2 02 Apr 2018, 16:29 UTC

NVIDIA GPU Display Driver contains a vulnerability in kernel mode layer handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges.

CVE-2018-6248 nvidia vulnerability CVSS: 7.2 02 Apr 2018, 16:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape where the software uses a sequential operation to read or write a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer which may lead to denial of service or possible escalation of privileges.

CVE-2018-6247 nvidia vulnerability CVSS: 7.2 02 Apr 2018, 16:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a NULL pointer dereference may lead to denial of service or possible escalation of privileges.

CVE-2017-6278 nvidia vulnerability CVSS: 4.6 26 Mar 2018, 16:29 UTC

NVIDIA Tegra kernel contains a vulnerability in the CORE DVFS Thermal driver where there is the potential to read or write a buffer using an index or pointer that references a memory location after the end of the buffer, which may lead to a denial of service or possible escalation of privileges.

CVE-2017-6296 nvidia vulnerability CVSS: 4.4 06 Mar 2018, 16:29 UTC

NVIDIA TrustZone Software contains a TOCTOU issue in the DRM application which may lead to the denial of service or possible escalation of privileges. This issue is rated as moderate.

CVE-2017-6295 nvidia vulnerability CVSS: 3.6 06 Mar 2018, 16:29 UTC

NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or information disclosure. This issue is rated as high.

CVE-2017-6284 nvidia vulnerability CVSS: 2.1 06 Mar 2018, 16:29 UTC

NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive data which may lead to information disclosure.This issue is rated as moderate.

CVE-2017-6283 nvidia vulnerability CVSS: 4.9 06 Mar 2018, 16:29 UTC

NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cleared on a chip reset which may lead to information disclosure. This issue is rated as high.

CVE-2017-6282 nvidia vulnerability CVSS: 7.2 06 Mar 2018, 16:29 UTC

NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as high.

CVE-2017-0866 nvidia vulnerability CVSS: 7.2 16 Nov 2017, 22:29 UTC

An elevation of privilege vulnerability in the Direct rendering infrastructure of the NVIDIA Tegra X1 where an unchecked input from userspace is passed as a pointer to kfree. This could lead to kernel memory corruption and possible code execution. This issue is rated as moderate. Product: Pixel. Version: N/A. Android ID: A-38415808. References: N-CVE-2017-0866.

CVE-2017-6273 nvidia vulnerability CVSS: 4.6 17 Oct 2017, 20:29 UTC

NVIDIA ADSP Firmware contains a vulnerability in the ADSP Loader component where there is the potential to write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service or possible escalation of privileges.

CVE-2017-0316 nvidia vulnerability CVSS: 4.6 16 Oct 2017, 21:29 UTC

In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemService64 where a value passed from a user to the driver is used without validation, which may lead to denial of service or possible escalation of privileges.

CVE-2017-14491 nvidia vulnerability CVSS: 7.5 04 Oct 2017, 01:29 UTC

Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.

CVE-2017-6277 nvidia vulnerability CVSS: 7.2 22 Sep 2017, 17:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or possible escalation of privileges.

CVE-2017-6272 nvidia vulnerability CVSS: 7.2 22 Sep 2017, 17:29 UTC

NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to a denial of service or possible escalation of privileges.

CVE-2017-6271 nvidia vulnerability CVSS: 4.9 22 Sep 2017, 17:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiCreateAllocation where untrusted user input is used as a divisor without validation while processing block linear information which may lead to a potential divide by zero and denial of service.

CVE-2017-6270 nvidia vulnerability CVSS: 4.9 22 Sep 2017, 17:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiCreateAllocation where untrusted user input is used as a divisor without validation during a calculation which may lead to a potential divide by zero and denial of service.

CVE-2017-6269 nvidia vulnerability CVSS: 7.2 22 Sep 2017, 17:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from a user to the driver is used without validation which may lead to denial of service or possible escalation of privileges.

CVE-2017-6268 nvidia vulnerability CVSS: 7.2 22 Sep 2017, 17:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or possible escalation of privileges.

CVE-2017-6267 nvidia vulnerability CVSS: 4.9 22 Sep 2017, 17:29 UTC

NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect initialization of internal objects can cause an infinite loop which may lead to a denial of service.

CVE-2017-6266 nvidia vulnerability CVSS: 4.9 22 Sep 2017, 17:29 UTC

NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where improper access controls could allow unprivileged users to cause a denial of service.

CVE-2017-1000251 nvidia vulnerability CVSS: 7.7 12 Sep 2017, 17:29 UTC

The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.

CVE-2017-6260 nvidia vulnerability CVSS: 4.9 28 Jul 2017, 19:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer helper function where an incorrect calculation of string length may lead to denial of service.

CVE-2017-6259 nvidia vulnerability CVSS: 7.1 28 Jul 2017, 19:29 UTC

NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect detection and recovery from an invalid state produced by specific user actions may lead to denial of service.

CVE-2017-6257 nvidia vulnerability CVSS: 7.2 28 Jul 2017, 19:29 UTC

NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges

CVE-2017-6256 nvidia vulnerability CVSS: 4.6 28 Jul 2017, 19:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array which may lead to denial of service or potential escalation of privileges.

CVE-2017-6255 nvidia vulnerability CVSS: 7.2 28 Jul 2017, 19:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an improper input parameter handling may lead to a denial of service or potential escalation of privileges.

CVE-2017-6254 nvidia vulnerability CVSS: 7.2 28 Jul 2017, 19:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from an user to the driver is used without validation which may lead to denial of service or potential escalation of privileges.

CVE-2017-6253 nvidia vulnerability CVSS: 7.2 28 Jul 2017, 19:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated which may lead to denial of service or potential escalation of privileges

CVE-2017-6252 nvidia vulnerability CVSS: 7.2 28 Jul 2017, 19:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler where a NULL pointer dereference may lead to a denial of service or potential escalation of privileges.

CVE-2017-6251 nvidia vulnerability CVSS: 7.2 28 Jul 2017, 19:29 UTC

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler where a missing permissions check may allow users to gain access to arbitrary physical system memory, which may lead to an escalation of privileges.

CVE-2017-0355 nvidia vulnerability CVSS: 4.9 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where it may access paged memory while holding a spinlock, leading to a denial of service.

CVE-2017-0354 nvidia vulnerability CVSS: 4.7 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where a call to certain function requiring lower IRQL can be made under raised IRQL which may lead to a denial of service.

CVE-2017-0353 nvidia vulnerability CVSS: 4.9 09 May 2017, 21:29 UTC

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where due to improper locking on certain conditions may lead to a denial of service

CVE-2017-0352 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the GPU firmware where incorrect access control may allow CPU access sensitive GPU control registers, leading to an escalation of privileges

CVE-2017-0351 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.

CVE-2017-0350 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used in an offset calculation may lead to denial of service or potential escalation of privileges.

CVE-2017-0349 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed from a user to the driver is not correctly validated before it is dereferenced for a write operation, may lead to denial of service or potential escalation of privileges.

CVE-2017-0348 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges.

CVE-2017-0347 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array, which may lead to denial of service or potential escalation of privileges.

CVE-2017-0346 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

CVE-2017-0345 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input used as an array size is not correctly validated allows out of bound access in kernel memory and may lead to denial of service or potential escalation of privileges

CVE-2017-0344 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape may allow users to gain access to arbitrary physical memory, leading to escalation of privileges.

CVE-2017-0343 nvidia vulnerability CVSS: 6.9 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) where user can trigger a race condition due to lack of synchronization in two functions leading to a denial of service or potential escalation of privileges.

CVE-2017-0342 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where incorrect calculation may cause an invalid address access leading to denial of service or potential escalation of privileges.

CVE-2017-0341 nvidia vulnerability CVSS: 7.2 09 May 2017, 21:29 UTC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input can trigger an access to a pointer that has not been initialized which may lead to denial of service or potential escalation of privileges.

CVE-2017-6250 nvidia vulnerability CVSS: 4.6 28 Apr 2017, 21:59 UTC

NVIDIA GeForce Experience contains a vulnerability in NVIDIA Web Helper.exe, where untrusted script execution may lead to violation of application execution policy and local code execution.

CVE-2016-6915 nvidia vulnerability CVSS: 7.2 24 Apr 2017, 20:59 UTC

Stack-based buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.

CVE-2016-6917 nvidia vulnerability CVSS: 7.2 24 Apr 2017, 19:59 UTC

Buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.

CVE-2016-6916 nvidia vulnerability CVSS: 7.2 24 Apr 2017, 19:59 UTC

Integer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5 allows local users to cause a denial of service (system crash) via unspecified vectors, which triggers a buffer overflow.

CVE-2017-5927 nvidia vulnerability CVSS: 5.0 27 Feb 2017, 07:59 UTC

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

CVE-2017-5926 nvidia vulnerability CVSS: 5.0 27 Feb 2017, 07:59 UTC

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

CVE-2017-5925 nvidia vulnerability CVSS: 5.0 27 Feb 2017, 07:59 UTC

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

CVE-2017-0324 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

CVE-2017-0323 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.

CVE-2017-0322 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a value passed from a user to the driver is not correctly validated and used as the index to an array, leading to denial of service or potential escalation of privileges.

CVE-2017-0321 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.

CVE-2017-0320 nvidia vulnerability CVSS: 4.9 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system.

CVE-2017-0319 nvidia vulnerability CVSS: 4.9 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper handling of values may cause a denial of service on the system.

CVE-2017-0318 nvidia vulnerability CVSS: 4.9 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Linux GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper validation of an input parameter may cause a denial of service on the system.

CVE-2017-0317 nvidia vulnerability CVSS: 6.9 15 Feb 2017, 23:59 UTC

All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permissions on the package extraction path thus allowing a non-privileged user to tamper with the extracted files, potentially leading to escalation of privileges via code execution.

CVE-2017-0315 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an attempt to access an invalid object pointer may lead to denial of service or potential escalation of privileges.

CVE-2017-0314 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges.

CVE-2017-0313 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implementation of the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual) where untrusted input is used to reference memory outside of the intended boundary of the buffer leading to denial of service or escalation of privileges.

CVE-2017-0312 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscapeID 0x100008b where user provided input is used as the limit for a loop may lead to denial of service or potential escalation of privileges

CVE-2017-0311 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

NVIDIA GPU Display Driver R378 contains a vulnerability in the kernel mode layer handler where improper access control may lead to denial of service or possible escalation of privileges.

CVE-2017-0310 nvidia vulnerability CVSS: 4.9 15 Feb 2017, 23:59 UTC

All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to cause a denial of service.

CVE-2017-0309 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where multiple integer overflows may cause improper memory allocation leading to a denial of service or potential escalation of privileges.

CVE-2017-0308 nvidia vulnerability CVSS: 7.2 15 Feb 2017, 23:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where untrusted input is used for buffer size calculation leading to denial of service or escalation of privileges.

CVE-2016-8827 nvidia vulnerability CVSS: 5.0 16 Dec 2016, 21:59 UTC

NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.

CVE-2016-8826 nvidia vulnerability CVSS: 4.9 16 Dec 2016, 21:59 UTC

All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys for Windows or nvidia.ko for Linux) where a user can cause a GPU interrupt storm, leading to a denial of service.

CVE-2016-8825 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

CVE-2016-8824 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where improper access controls allow a regular user to write a part of the registry intended for privileged users only, leading to escalation of privileges.

CVE-2016-8823 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where the size of an input buffer is not validated leading to a denial of service or possible escalation of privileges

CVE-2016-8822 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x600000E, 0x600000F, and 0x6000010 where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

CVE-2016-8821 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where improper access controls may allow a user to access arbitrary physical memory, leading to an escalation of privileges.

CVE-2016-8820 nvidia vulnerability CVSS: 5.6 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a check on a function return value is missing, potentially allowing an uninitialized value to be used as the source of a strcpy() call, leading to denial of service or information disclosure.

CVE-2016-8819 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a handle to a kernel object may be returned to the user, leading to possible denial of service or escalation of privileges.

CVE-2016-8818 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a pointer passed from a user to the driver is used without validation, leading to denial of service or potential escalation of privileges.

CVE-2016-8817 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the size input to memcpy(), causing a buffer overflow, leading to denial of service or potential escalation of privileges.

CVE-2016-8816 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the index to an array, leading to denial of service or potential escalation of privileges.

CVE-2016-8815 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a value passed from a user to the driver is used without validation as the index to an array, leading to denial of service or potential escalation of privileges.

CVE-2016-8814 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where multiple pointers are used without checking for NULL, leading to denial of service or potential escalation of privileges.

CVE-2016-8813 nvidia vulnerability CVSS: 7.2 16 Dec 2016, 21:59 UTC

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where multiple pointers are used without checking for NULL, leading to denial of service or potential escalation of privileges.

CVE-2016-8812 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode layer (nvstreamkms.sys) allowing a user to cause a stack buffer overflow with specially crafted executable paths, leading to a denial of service or escalation of privileges.

CVE-2016-8811 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

CVE-2016-8810 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100009a where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

CVE-2016-8809 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70001b2 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

CVE-2016-8808 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000d5 where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

CVE-2016-8807 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x10000e9 where a value is passed from an user to the driver is used without validation as the size input to memcpy() causing a stack buffer overflow, leading to denial of service or potential escalation of privileges.

CVE-2016-8806 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x5000027 where a pointer passed from an user to the driver is used without validation, leading to denial of service or potential escalation of privileges.

CVE-2016-8805 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000014 where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

CVE-2016-7391 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100010b where a missing array bounds check can allow a user to write to kernel memory, leading to denial of service or potential escalation of privileges.

CVE-2016-7390 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000194 where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

CVE-2016-7389 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.

CVE-2016-7388 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where a NULL pointer dereference caused by invalid user input may lead to denial of service or potential escalation of privileges.

CVE-2016-7387 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x600000D where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

CVE-2016-7386 nvidia vulnerability CVSS: 2.1 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000D4 which may lead to leaking of kernel memory contents to user space through an uninitialized buffer.

CVE-2016-7385 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x700010d where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

CVE-2016-7384 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) where unchecked input/output lengths in UVMLiteController Device IO Control handling may lead to denial of service or potential escalation of privileges.

CVE-2016-7383 nvidia vulnerability CVSS: 6.1 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in a memory mapping API in the kernel mode layer (nvlddmkm.sys) handler, leading to denial of service or potential escalation of privileges.

CVE-2016-7382 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys for Windows or nvidia.ko for Linux) handler where a missing permissions check may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.

CVE-2016-7381 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a user input to index an array is not bounds checked, leading to denial of service or potential escalation of privileges.

CVE-2016-5852 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows. A successful exploit of a vulnerable service installation can enable malicious code to execute on the system at the system/user privilege level. The CVE-2016-5852 ID is for the NVTray Plugin unquoted service path.

CVE-2016-5025 nvidia vulnerability CVSS: 6.1 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, improper sanitization of parameters in the NVAPI support layer causes a denial of service vulnerability (blue screen crash) within the NVIDIA Windows graphics drivers.

CVE-2016-4961 nvidia vulnerability CVSS: 4.9 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, improper sanitization of parameters in the NVStreamKMS.sys API layer caused a denial of service vulnerability (blue screen crash) within the NVIDIA Windows graphics drivers.

CVE-2016-4960 nvidia vulnerability CVSS: 6.9 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, the NVIDIA NVStreamKMS.sys service component is improperly validating user-supplied data through its API entry points causing an elevation of privilege.

CVE-2016-4959 nvidia vulnerability CVSS: 7.8 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, there is a Remote Desktop denial of service. A successful exploit of a vulnerable system will result in a kernel null pointer dereference, causing a blue screen crash.

CVE-2016-3161 nvidia vulnerability CVSS: 7.2 08 Nov 2016, 20:59 UTC

For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows. A successful exploit of a vulnerable service installation can enable malicious code to execute on the system at the system/user privilege level. The CVE-2016-3161 ID is for the GameStream unquoted service path.

CVE-2016-2558 nvidia vulnerability CVSS: 7.2 12 Apr 2016, 14:59 UTC

The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows allows local users to obtain sensitive information, cause a denial of service (crash), or gain privileges via unspecified vectors related to an untrusted pointer, which trigger uninitialized or out-of-bounds memory access.

CVE-2016-2557 nvidia vulnerability CVSS: 7.2 12 Apr 2016, 14:59 UTC

The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows allows local users to obtain sensitive information from kernel memory, cause a denial of service (crash), or possibly gain privileges via unspecified vectors, which trigger uninitialized or out-of-bounds memory access.

CVE-2016-2556 nvidia vulnerability CVSS: 7.2 12 Apr 2016, 14:59 UTC

The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows improperly allows access to restricted functionality, which allows local users to gain privileges via unspecified vectors.

CVE-2015-8328 nvidia vulnerability CVSS: 6.6 24 Nov 2015, 20:59 UTC

Unspecified vulnerability in the NVAPI support layer in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows allows local users to obtain sensitive information, cause a denial of service (crash), or possibly gain privileges via unknown vectors. NOTE: this identifier was SPLIT from CVE-2015-7869 per ADT2 and ADT3 due to different vulnerability types and affected versions.

CVE-2015-7869 nvidia vulnerability CVSS: 6.6 24 Nov 2015, 20:59 UTC

Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows and R304 before 304.131, R340 before 340.96, R352 before 352.63, and R358 before 358.16 on Linux allow local users to obtain sensitive information, cause a denial of service (crash), or possibly gain privileges via unknown vectors, which trigger uninitialized or out of bounds memory access. NOTE: this identifier has been SPLIT per ADT2 and ADT3 due to different vulnerability type and affected versions. See CVE-2015-8328 for the vulnerability in the NVAPI support layer in NVIDIA drivers for Windows.

CVE-2015-7866 nvidia vulnerability CVSS: 7.2 24 Nov 2015, 20:59 UTC

Unquoted Windows search path vulnerability in the Smart Maximize Helper (nvSmartMaxApp.exe) in the Control Panel in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows allows local users to gain privileges via a Trojan horse application, as demonstrated by C:\Program.exe.

CVE-2015-7865 nvidia vulnerability CVSS: 7.7 24 Nov 2015, 20:59 UTC

nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows does not properly restrict access to the stereosvrpipe named pipe, which allows local users to gain privileges via a commandline in a number 2 command, which is stored in the HKEY_LOCAL_MACHINE explorer Run registry key, a different vulnerability than CVE-2011-4784.

CVE-2015-5053 nvidia vulnerability CVSS: 10.0 24 Nov 2015, 20:59 UTC

The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the follow_pfn kernel-mode API call.

CVE-2015-5950 nvidia vulnerability CVSS: 6.9 30 Sep 2015, 01:59 UTC

The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 before 304.128, R340 before 340.93, and R352 before 352.41 on Linux; and R352 before 352.46 on GRID vGPU and vSGA allows local users to write to an arbitrary kernel memory location and consequently gain privileges via a crafted ioctl call.

CVE-2015-3625 nvidia vulnerability CVSS: 7.2 18 Jul 2015, 00:59 UTC

The NVIDIA GPU driver for FreeBSD R352 before 352.09, 346 before 346.72, R349 before 349.16, R343 before 343.36, R340 before 340.76, R337 before 337.25, R334 before 334.21, R331 before 331.113, and R304 before 304.125 allows local users with certain permissions to read or write arbitrary kernel memory via unspecified vectors that trigger an untrusted pointer dereference.

CVE-2015-1170 nvidia vulnerability CVSS: 7.2 06 Mar 2015, 23:59 UTC

The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not properly validate local client impersonation levels when performing a "kernel administrator check," which allows local users to gain administrator privileges via unspecified API calls.

CVE-2014-8298 nvidia vulnerability CVSS: 7.5 10 Dec 2014, 15:59 UTC

The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.

CVE-2013-5987 nvidia vulnerability CVSS: 7.2 21 Jan 2014, 18:55 UTC

Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 allows local users to bypass intended access restrictions for the GPU and gain privileges via unknown vectors.

CVE-2013-5986 nvidia vulnerability CVSS: 10.0 21 Jan 2014, 18:55 UTC

Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 has unknown impact and attack vectors, a different vulnerability than CVE-2013-5987.

CVE-2013-0131 nvidia vulnerability CVSS: 7.1 08 Apr 2013, 16:55 UTC

Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout mode is enabled, allows remote authenticated users to execute arbitrary code via a large ARGB cursor.

CVE-2013-0111 nvidia vulnerability CVSS: 6.8 08 Apr 2013, 16:55 UTC

daemonu.exe (aka the NVIDIA Update Service Daemon), as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program.

CVE-2013-0110 nvidia vulnerability CVSS: 6.8 08 Apr 2013, 16:55 UTC

nvSCPAPISvr.exe in the NVIDIA Stereoscopic 3D Driver service, as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program.

CVE-2013-0109 nvidia vulnerability CVSS: 7.2 08 Apr 2013, 16:55 UTC

The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, which allows local users to gain privileges or cause a denial of service (memory overwrite) via a crafted application.

CVE-2011-2603 nvidia vulnerability CVSS: 7.1 30 Jun 2011, 15:55 UTC

The NVIDIA 9400M driver 6.2.6 on Mac OS X 10.6.7 allows remote attackers to cause a denial of service (desktop hang) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in the Khronos WebGL SDK.

CVE-2011-2602 nvidia vulnerability CVSS: 7.1 30 Jun 2011, 15:55 UTC

The NVIDIA Geforce 310 driver 6.14.12.7061 on Windows XP SP3 allows remote attackers to cause a denial of service (system crash) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in the Khronos WebGL SDK.

CVE-2011-0636 nvidia vulnerability CVSS: 2.1 22 Jan 2011, 22:00 UTC

The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations.

CVE-2006-6340 nvidia vulnerability CVSS: 5.0 07 Dec 2006, 01:28 UTC

keystone.exe in nVIDIA nView allows attackers to cause a denial of service via a long command line argument. NOTE: it is not clear whether this issue crosses security boundaries. If not, then this is not a vulnerability.

CVE-2006-5379 nvidia vulnerability CVSS: 7.5 18 Oct 2006, 04:06 UTC

The accelerated rendering functionality of NVIDIA Binary Graphics Driver (binary blob driver) For Linux v8774 and v8762, and probably on other operating systems, allows local and remote attackers to execute arbitrary code via a large width value in a font glyph, which can be used to overwrite arbitrary memory locations.