VYPR

Vendor CVEs

Nvidia

All CVEs

1,157 total · sorted by risk
  • CVE-2023-31010MedSep 20, 2023
    risk 0.44cvss 6.8epss 0.01

    NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, and denial of service.

  • CVE-2023-25508MedApr 22, 2023
    risk 0.44cvss 6.7epss 0.00

    NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information…

  • CVE-2023-0201MedApr 22, 2023
    risk 0.44cvss 6.7epss 0.00

    NVIDIA DGX-2 SBIOS contains a vulnerability in Bds, where a user with high privileges can cause a write beyond the bounds of an indexable resource, which may lead to code execution, denial of service, compromised integrity, and information disclosure.

  • CVE-2023-0185MedApr 1, 2023
    risk 0.44cvss 6.7epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where sign conversion issuescasting an unsigned primitive to signed may lead to denial of service or information disclosure.

  • CVE-2022-31611MedFeb 7, 2023
    risk 0.44cvss 6.8epss 0.00

    NVIDIA GeForce Experience contains an uncontrolled search path vulnerability in all its client installers, where an attacker with user level privileges may cause the installer to load an arbitrary DLL when the installer is launched. A successful exploit of this vulnerability…

  • CVE-2022-42281MedJan 13, 2023
    risk 0.44cvss 6.7epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the FsRecovery, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure.

  • CVE-2022-34674MedDec 30, 2022
    risk 0.44cvss 6.8epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where a helper function maps more physical pages than were requested, which may lead to undefined behavior or an information leak.

  • CVE-2022-31601MedJul 4, 2022
    risk 0.44cvss 6.7epss 0.00

    NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmbiosPei, which may allow a highly privileged local attacker to cause an out-of-bounds write, which may lead to code execution, denial of service, compromised integrity, and information disclosure.

  • CVE-2022-28185MedMay 17, 2022
    risk 0.44cvss 6.8epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to denial of service and data tampering.

  • CVE-2021-34402MedJan 18, 2022
    risk 0.44cvss 6.7epss 0.00

    NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service, Information disclosure, loss…

  • CVE-2021-1111MedAug 11, 2021
    risk 0.44cvss 6.7epss 0.00

    Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to buffer overflow, resulting in limited information disclosure, limited data integrity, and denial of service across all…

  • CVE-2021-34382MedJun 30, 2021
    risk 0.44cvss 6.7epss 0.00

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel’s tz_map_shared_mem function where an integer overflow on the size parameter causes the request buffer and the logging buffer to overflow, allowing writes to arbitrary addresses within the kernel.

  • CVE-2021-34381MedJun 30, 2021
    risk 0.44cvss 6.7epss 0.00

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow on the size parameter of the tz_map_shared_mem function, which might lead to denial of service, information disclosure, or data tampering.

  • CVE-2021-1067MedJan 20, 2021
    risk 0.44cvss 6.8epss 0.00

    NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the implementation of the RPMB command status, in which an attacker can write to the Write Protect Configuration Block, which may lead to denial of service or escalation of privileges.

  • CVE-2020-11488MedOct 29, 2020
    risk 0.44cvss 6.7epss 0.00

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public key used to verify the firmware…

  • CVE-2019-5688MedNov 18, 2019
    risk 0.44cvss 6.7epss 0.00

    NVIDIA NVFlash, NVUFlash Tool prior to v5.588.0 and GPUModeSwitch Tool prior to 2019-11, NVIDIA kernel mode driver (nvflash.sys, nvflsh32.sys, and nvflsh64.sys) contains a vulnerability in which authenticated users with administrative privileges can gain access to device memory…

  • CVE-2019-5680MedJul 19, 2019
    risk 0.44cvss 6.7epss 0.00

    In NVIDIA Jetson TX1 L4T R32 version branch prior to R32.2, Tegra bootloader contains a vulnerability in nvtboot in which the nvtboot-cpu image is loaded without the load address first being validated, which may lead to code execution, denial of service, or escalation of…

  • CVE-2019-5676MedMay 10, 2019
    risk 0.44cvss 6.7epss 0.01

    NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of…

  • CVE-2018-3639MedMay 22, 2018
    risk 0.44cvss 5.5epss 0.61

    Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis,…

  • CVE-2018-6242MedMay 1, 2018
    risk 0.44cvss 6.8epss 0.02

    Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to…

  • CVE-2026-47619MedAug 4, 2026
    risk 0.43cvss 6.6epss 0.00

    NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

  • CVE-2023-31034MedJan 12, 2024
    risk 0.43cvss 6.6epss 0.00

    NVIDIA DGX A100 SBIOS contains a vulnerability where a local attacker can cause input validation checks to be bypassed by causing an integer overflow. A successful exploit of this vulnerability may lead to denial of service, information disclosure, and data tampering.

  • CVE-2023-31015MedSep 20, 2023
    risk 0.43cvss 6.6epss 0.00

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service where a host user may cause as improper authentication issue. A successful exploit of this vulnerability may lead to escalation of privileges, information disclosure, code execution, and denial of service.

  • CVE-2023-0198MedApr 1, 2023
    risk 0.43cvss 6.6epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where improper restriction of operations within the bounds of a memory buffer can lead to denial of service, information disclosure, and data tampering.

  • CVE-2022-28198MedApr 29, 2022
    risk 0.43cvss 6.6epss 0.00

    NVIDIA Omniverse Nucleus and Cache contain a vulnerability in its configuration of OpenSSL, where an attacker with physical access to the system can cause arbitrary code execution which can impact confidentiality, integrity, and availability.

  • CVE-2021-1077MedApr 21, 2021
    risk 0.43cvss 6.6epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux, R450 and R460 driver branch, contains a vulnerability where the software uses a reference count to manage a resource that is incorrectly updated, which may lead to denial of service.

  • CVE-2021-1076MedApr 21, 2021
    risk 0.43cvss 6.6epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys or nvidia.ko) where improper access control may lead to denial of service, information disclosure, or data corruption.

  • CVE-2016-8827MedDec 16, 2016
    risk 0.43cvss 6.5epss 0.05

    NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.

  • CVE-2016-5025MedNov 8, 2016
    risk 0.43cvss 6.6epss 0.00

    For the NVIDIA Quadro, NVS, and GeForce products, improper sanitization of parameters in the NVAPI support layer causes a denial of service vulnerability (blue screen crash) within the NVIDIA Windows graphics drivers.

  • CVE-2026-47606MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.01

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.

  • CVE-2026-47621MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2026-47620MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.

  • CVE-2026-24220MedJul 14, 2026
    risk 0.42cvss 6.4epss 0.00

    NVIDIA TensorRT-LLM for any platform contains a vulnerability in visual gen server, where an attacker could cause an unsafe deserialization by unauthorized zeroMQ deserialization. A successful exploit of this vulnerability might lead to code execution.

  • CVE-2026-24197MedMay 26, 2026
    risk 0.42cvss 6.5epss 0.00

    NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful…

  • CVE-2026-24182MedMay 26, 2026
    risk 0.42cvss 6.5epss 0.00

    NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could leak held driver locks. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-33202MedNov 11, 2025
    risk 0.42cvss 6.5epss 0.00

    NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where an attacker could cause a stack overflow by sending extra-large payloads. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-23259MedSep 4, 2025
    risk 0.42cvss 6.5epss 0.00

    NVIDIA Mellanox DPDK contains a vulnerability in Poll Mode Driver (PMD), where an attacker on a VM in the system might be able to cause information disclosure and denial of service on the network interface.

  • CVE-2025-23243MedMar 11, 2025
    risk 0.42cvss 6.5epss 0.02

    NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to data tampering or denial of service.

  • CVE-2024-0093MedJun 13, 2024
    risk 0.42cvss 6.5epss 0.00

    NVIDIA GPU software for Linux contains a vulnerability where it can expose sensitive information to an actor that is not explicitly authorized to have access to that information. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2024-0100MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.01

    NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a user can corrupt system files. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2024-0083MedApr 8, 2024
    risk 0.42cvss 6.5epss 0.01

    NVIDIA ChatRTX for Windows contains a vulnerability in the UI, where an attacker can cause a cross-site scripting error by network by running malicious scripts in users' browsers. A successful exploit of this vulnerability might lead to code execution, denial of service, and…

  • CVE-2024-0079MedMar 27, 2024
    risk 0.42cvss 6.5epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest VM can cause a NULL-pointer dereference in the host. A successful exploit of this vulnerability may lead to denial of service.

  • CVE-2024-0078MedMar 27, 2024
    risk 0.42cvss 6.5epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user in a guest can cause a NULL-pointer dereference in the host, which may lead to denial of service.

  • CVE-2023-31025MedJan 12, 2024
    risk 0.42cvss 6.5epss 0.00

    NVIDIA DGX A100 BMC contains a vulnerability where an attacker may cause an LDAP user injection. A successful exploit of this vulnerability may lead to information disclosure.

  • CVE-2023-31018MedNov 2, 2023
    risk 0.42cvss 6.5epss 0.00

    NVIDIA GPU Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause a NULL-pointer dereference, which may lead to denial of service.

  • CVE-2023-25532MedSep 20, 2023
    risk 0.42cvss 6.5epss 0.01

    NVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploit of this vulnerability may lead to information disclosure.

  • CVE-2023-25526MedSep 20, 2023
    risk 0.42cvss 6.5epss 0.00

    NVIDIA Cumulus Linux contains a vulnerability in neighmgrd and nlmanager where an attacker on an adjacent network may cause an uncaught exception by injecting a crafted packet. A successful exploit may lead to denial of service.

  • CVE-2023-0204MedApr 22, 2023
    risk 0.42cvss 6.5epss 0.00

    NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX contain a vulnerability in the NIC firmware, where an unprivileged user can cause improper handling of exceptional conditions, which may lead to denial of service.

  • CVE-2022-42283MedJan 13, 2023
    risk 0.42cvss 6.4epss 0.00

    NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

  • CVE-2022-42282MedJan 13, 2023
    risk 0.42cvss 6.5epss 0.00

    NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can access arbitrary files, which may lead to information disclosure.

Page 15 of 24