VYPR

Vendor CVEs

Nvidia

All CVEs

1,089 total · sorted by risk
  • CVE-2017-0310MedFeb 15, 2017
    risk 0.42cvss 6.5epss 0.00

    All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileged user to cause a denial of service.

  • CVE-2026-24142MedMay 20, 2026
    risk 0.41cvss 6.3epss 0.00

    NVIDIA TRT-LLM for any platform contains a deserialization vulnerability and unsafe serialized handle. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-24231MedApr 28, 2026
    risk 0.41cvss 6.3epss 0.00

    NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI…

  • CVE-2025-23262MedSep 4, 2025
    risk 0.41cvss 6.3epss 0.00

    NVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorization to modify the configuration. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges,…

  • CVE-2024-0129MedOct 15, 2024
    risk 0.41cvss 6.3epss 0.00

    NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering.

  • CVE-2024-0085MedJun 13, 2024
    risk 0.41cvss 6.3epss 0.00

    NVIDIA vGPU software for Windows and Linux contains a vulnerability where unprivileged users could execute privileged operations on the host. A successful exploit of this vulnerability might lead to data tampering, escalation of privileges, and denial of service.

  • CVE-2021-34385MedJun 30, 2021
    risk 0.41cvss 6.3epss 0.00

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calculation of a length could lead to a heap overflow.

  • CVE-2021-34384MedJun 30, 2021
    risk 0.41cvss 6.3epss 0.00

    Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow could cause memory corruption, which might lead to denial of service or code execution.

  • CVE-2021-34388MedJun 21, 2021
    risk 0.41cvss 6.3epss 0.00

    Bootloader contains a vulnerability in NVIDIA TegraBoot where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.

  • CVE-2021-34387MedJun 21, 2021
    risk 0.41cvss 6.3epss 0.00

    The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and…

  • CVE-2021-34386MedJun 21, 2021
    risk 0.41cvss 6.3epss 0.00

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calloc size calculation can cause the multiplication of count and size can overflow, which might lead to heap overflows.

  • CVE-2021-1061MedJan 8, 2021
    risk 0.41cvss 6.3epss 0.00

    NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version…

  • CVE-2020-5969MedJun 30, 2020
    risk 0.41cvss 6.3epss 0.00

    NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which it validates a shared resource before using it, creating a race condition which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x…

  • CVE-2025-33176MedNov 4, 2025
    risk 0.40cvss 6.2epss 0.00

    NVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communications channels on an adjacent network. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, and information…

  • CVE-2024-0115MedAug 12, 2024
    risk 0.40cvss 6.1epss 0.00

    NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue by a long running CV-CUDA Python process. A successful exploit of this vulnerability may lead to denial of service…

  • CVE-2024-0075MedMar 27, 2024
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where a user may cause a NULL-pointer dereference by accessing passed parameters the validity of which has not been checked. A successful exploit of this vulnerability may lead to denial of service and…

  • CVE-2023-31020MedNov 2, 2023
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause improper access control, which may lead to denial of service or data tampering.

  • CVE-2023-31013MedSep 20, 2023
    risk 0.40cvss 6.1epss 0.01

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure.

  • CVE-2023-31012MedSep 20, 2023
    risk 0.40cvss 6.1epss 0.01

    NVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploit of this vulnerability may lead to escalation of privileges and information disclosure.

  • CVE-2023-0199MedApr 22, 2023
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds write can lead to denial of service and data tampering.

  • CVE-2023-0187MedApr 1, 2023
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read can lead to denial of service.

  • CVE-2023-0186MedApr 1, 2023
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service and data tampering.

  • CVE-2022-42284MedJan 13, 2023
    risk 0.40cvss 6.2epss 0.00

    NVIDIA BMC stores user passwords in an obfuscated form in a database accessible by the host. This may lead to a credentials exposure.

  • CVE-2022-31616MedNov 19, 2022
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to denial of service, or information disclosure.

  • CVE-2022-28186MedMay 17, 2022
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to…

  • CVE-2022-21814MedFeb 7, 2022
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service.

  • CVE-2022-21813MedFeb 7, 2022
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of service.

  • CVE-2021-1094MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.

  • CVE-2021-1093MedJul 22, 2021
    risk 0.40cvss 6.2epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may…

  • CVE-2021-1100MedJul 21, 2021
    risk 0.40cvss 6.2epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel mode driver (nvidia.ko), in which a pointer to a user-space buffer is not validated before it is dereferenced, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3),…

  • CVE-2021-1079MedApr 20, 2021
    risk 0.40cvss 6.1epss 0.00

    NVIDIA GeForce Experience, all versions prior to 3.22, contains a vulnerability in GameStream plugins where log files are created using NT/System level permissions, which may lead to code execution, denial of service, or local privilege escalation. The attacker does not have…

  • CVE-2021-1069MedJan 20, 2021
    risk 0.40cvss 6.1epss 0.00

    NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the NVHost function, which may lead to abnormal reboot due to a null pointer reference, causing data loss.

  • CVE-2019-5673MedApr 11, 2019
    risk 0.40cvss 6.1epss 0.00

    NVIDIA Jetson TX2 contains a vulnerability in the kernel driver (on all versions prior to R28.3) where the ARM System Memory Management Unit (SMMU) improperly checks for a fault condition, causing transactions to be discarded, which may lead to denial of service.

  • CVE-2017-6259MedJul 28, 2017
    risk 0.40cvss 6.1epss 0.01

    NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect detection and recovery from an invalid state produced by specific user actions may lead to denial of service.

  • CVE-2016-8820MedDec 16, 2016
    risk 0.40cvss 6.1epss 0.00

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a check on a function return value is missing, potentially allowing an uninitialized value to be used as the source of a strcpy()…

  • CVE-2026-64460HigJul 25, 2026
    risk 0.39cvss 7.0epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: PCI/IOV: Skip VF Resizable BAR restore on read error sriov_restore_vf_rebar_state() uses the VF Resizable BAR Control register to decide how many VF BARs to restore (nbars) and which VF BAR each iteration…

  • CVE-2023-31026MedNov 2, 2023
    risk 0.39cvss 6.0epss 0.00

    NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a NULL-pointer dereference may lead to denial of service.

  • CVE-2023-25509MedApr 22, 2023
    risk 0.39cvss 6.0epss 0.00

    NVIDIA DGX-1 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, and escalation of privileges.

  • CVE-2022-42287MedJan 13, 2023
    risk 0.39cvss 6.0epss 0.00

    NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalation of privileges, information disclosure and data tampering.

  • CVE-2022-42286MedJan 13, 2023
    risk 0.39cvss 6.0epss 0.00

    DGX A100 SBIOS contains a vulnerability in Bds, which may lead to code execution, denial of service, or escalation of privileges.

  • CVE-2022-42285MedJan 13, 2023
    risk 0.39cvss 6.0epss 0.00

    DGX A100 SBIOS contains a vulnerability in the Pre-EFI Initialization (PEI)phase, where a privileged user can disable SPI flash protection, which may lead to denial of service, escalation of privileges, or data tampering.

  • CVE-2021-1072MedFeb 5, 2021
    risk 0.39cvss 6.0epss 0.00

    NVIDIA GeForce Experience, all versions prior to 3.21, contains a vulnerability in GameStream (rxdiag.dll) where an arbitrary file deletion due to improper handling of log files may lead to denial of service.

  • CVE-2016-7386MedNov 8, 2016
    risk 0.39cvss 5.5epss 0.01

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000D4 which may lead to leaking of kernel memory…

  • CVE-2026-24201MedMay 26, 2026
    risk 0.38cvss 5.8epss 0.00

    NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering, denial of service, or information disclosure.

  • CVE-2025-33242MedMar 24, 2026
    risk 0.38cvss 5.9epss 0.00

    NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registries, causing a bad state. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2025-23334MedAug 6, 2025
    risk 0.38cvss 5.9epss 0.01

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by sending a request. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2025-23333MedAug 6, 2025
    risk 0.38cvss 5.9epss 0.00

    NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds read by manipulating shared memory data. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-24215MedMay 20, 2026
    risk 0.37cvss 5.7epss 0.00

    NVIDIA Triton Inference Server contains a vulnerability in the DALI backend, where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-33194MedNov 25, 2025
    risk 0.37cvss 5.7epss 0.00

    NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper processing of input data. A successful exploit of this vulnerability might lead to information disclosure or denial of service.

  • CVE-2025-33193MedNov 25, 2025
    risk 0.37cvss 5.7epss 0.00

    NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of integrity. A successful exploit of this vulnerability might lead to information disclosure.

Page 15 of 22