VYPR

Vendor CVEs

Nvidia

All CVEs

1,011 total · sorted by risk
  • CVE-2021-34398Aug 13, 2021
    risk 0.00cvss epss 0.00

    NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared libraries into the DCGM server, which is usually running as root, which may lead to privilege escalation, total loss of confidentiality and integrity, and…

  • CVE-2021-1114Aug 11, 2021
    risk 0.00cvss epss 0.00

    NVIDIA Linux kernel distributions contain a vulnerability in the kernel crypto node, where use after free may lead to complete denial of service.

  • CVE-2021-1113Aug 11, 2021
    risk 0.00cvss epss 0.00

    NVIDIA camera firmware contains a difficult to exploit vulnerability where a highly privileged attacker can cause unauthorized modification to camera resources, which may result in complete denial of service and partial loss of data integrity for all clients.

  • CVE-2021-1112Aug 11, 2021
    risk 0.00cvss epss 0.00

    NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where a null pointer dereference may lead to complete denial of service.

  • CVE-2021-1111Aug 11, 2021
    risk 0.00cvss epss 0.00

    Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to buffer overflow, resulting in limited information disclosure, limited data integrity, and denial of service across all…

  • CVE-2021-1110Aug 11, 2021
    risk 0.00cvss epss 0.00

    NVIDIA Linux kernel distributions on Jetson Xavier contain a vulnerability in camera firmware where a user can change input data after validation, which may lead to complete denial of service and serious data corruption of all kernel components.

  • CVE-2021-1109Aug 11, 2021
    risk 0.00cvss epss 0.00

    NVIDIA camera firmware contains a multistep, timing-related vulnerability where an unauthorized modification by camera resources may result in loss of data integrity or denial of service across several streams.

  • CVE-2021-1108Aug 11, 2021
    risk 0.00cvss epss 0.00

    NVIDIA Linux kernel distributions contain a vulnerability in FuSa Capture (VI/ISP), where integer underflow due to lack of input validation may lead to complete denial of service, partial integrity, and serious confidentiality loss for all processes in the system.

  • CVE-2021-1107Aug 11, 2021
    risk 0.00cvss epss 0.00

    NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVMAP_IOC_WRITE* paths, where improper access controls may lead to code execution, complete denial of service, and seriously compromised integrity of all system components.

  • CVE-2021-1106Aug 11, 2021
    risk 0.00cvss epss 0.00

    NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where writes may be allowed to read-only buffers, which may result in escalation of privileges, complete denial of service, unconstrained information disclosure, and serious data tampering of all processes on…

  • CVE-2021-1096Jul 22, 2021
    risk 0.00cvss epss 0.00

    NVIDIA Windows GPU Display Driver for Windows contains a vulnerability in the NVIDIA kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where dereferencing a NULL pointer may lead to a system crash.

  • CVE-2021-1092Jul 22, 2021
    risk 0.00cvss epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overwrite privileged files, resulting in…

  • CVE-2021-1091Jul 22, 2021
    risk 0.00cvss epss 0.00

    NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overwrite a file that requires elevated privilege to modify, which could lead to data loss or denial of service.

  • CVE-2021-1089Jul 22, 2021
    risk 0.00cvss epss 0.00

    NVIDIA GPU Display Driver for Windows contains a vulnerability in nvidia-smi where an uncontrolled DLL loading path may lead to arbitrary code execution, denial of service, information disclosure, and data tampering.

  • CVE-2021-1094Jul 22, 2021
    risk 0.00cvss epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.

  • CVE-2021-1093Jul 22, 2021
    risk 0.00cvss epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may…

  • CVE-2021-1090Jul 22, 2021
    risk 0.00cvss epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for control calls where the software reads or writes to a buffer by using an index or pointer that references a memory location after the end of the buffer,…

  • CVE-2021-1095Jul 22, 2021
    risk 0.00cvss epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.

  • CVE-2021-1103Jul 21, 2021
    risk 0.00cvss epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

  • CVE-2021-1102Jul 21, 2021
    risk 0.00cvss epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can lead to floating point exceptions, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

  • CVE-2021-1101Jul 21, 2021
    risk 0.00cvss epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

  • CVE-2021-1100Jul 21, 2021
    risk 0.00cvss epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel mode driver (nvidia.ko), in which a pointer to a user-space buffer is not validated before it is dereferenced, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3),…

  • CVE-2021-1099Jul 21, 2021
    risk 0.00cvss epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) that could allow an attacker to cause stack-based buffer overflow and put a customized ROP gadget on the stack. Such an attack may lead to information disclosure, data tampering, or denial of…

  • CVE-2021-1098Jul 21, 2021
    risk 0.00cvss epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it doesn't release some resources during driver unload requests from guests. This flaw allows a malicious guest to perform operations by reusing those resources, which may lead to…

  • CVE-2021-1097Jul 21, 2021
    risk 0.00cvss epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it improperly validates the length field in a request from a guest. This flaw allows a malicious guest to send a length field that is inconsistent with the actual length of the input,…

  • CVE-2021-34385Jun 30, 2021
    risk 0.00cvss epss 0.00

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calculation of a length could lead to a heap overflow.

  • CVE-2021-34384Jun 30, 2021
    risk 0.00cvss epss 0.00

    Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow could cause memory corruption, which might lead to denial of service or code execution.

  • CVE-2021-34383Jun 30, 2021
    risk 0.00cvss epss 0.00

    Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow might lead to denial of service or escalation of privileges.

  • CVE-2021-34382Jun 30, 2021
    risk 0.00cvss epss 0.00

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel’s tz_map_shared_mem function where an integer overflow on the size parameter causes the request buffer and the logging buffer to overflow, allowing writes to arbitrary addresses within the kernel.

  • CVE-2021-34381Jun 30, 2021
    risk 0.00cvss epss 0.00

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow on the size parameter of the tz_map_shared_mem function, which might lead to denial of service, information disclosure, or data tampering.

  • CVE-2021-34380Jun 30, 2021
    risk 0.00cvss epss 0.00

    Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and information disclosure during secure boot.

  • CVE-2021-34379Jun 30, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an I/O buffer parameter is not checked, which might lead to memory corruption.

  • CVE-2021-34378Jun 30, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 11 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to information disclosure, denial of service, or escalation of privileges.

  • CVE-2021-34377Jun 30, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 9 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to escalation of privileges, information disclosure, and denial of service.

  • CVE-2021-34376Jun 30, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 5 is missing. Improper restriction of operations within the bounds of a memory buffer might lead to denial of service, escalation of privileges, and information disclosure.

  • CVE-2021-34375Jun 30, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in all trusted applications (TAs) where the stack cookie was not randomized, which might result in stack-based buffer overflow, leading to denial of service, escalation of privileges, and information disclosure.

  • CVE-2021-34374Jun 30, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerability can cause memory corruption, which may lead to information disclosure, escalation of privileges, and denial of service.

  • CVE-2021-34373Jun 30, 2021
    risk 0.00cvss epss 0.00

    Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could cause heap overflows, which might lead to information disclosure and denial of service.

  • CVE-2021-1073Jun 25, 2021
    risk 0.00cvss epss 0.01

    NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to log in by using a browser, while, at the same time, any other web page is loaded in other tabs of the same browser. In this situation, the web page can get…

  • CVE-2021-34397Jun 22, 2021
    risk 0.00cvss epss 0.00

    Bootloader contains a vulnerability in NVIDIA MB2, which may cause free-the-wrong-heap, which may lead to limited denial of service.

  • CVE-2021-34396Jun 22, 2021
    risk 0.00cvss epss 0.00

    Bootloader contains a vulnerability in access permission settings where unauthorized software may be able to overwrite NVIDIA MB2 code, which would result in limited denial of service.

  • CVE-2021-34395Jun 22, 2021
    risk 0.00cvss epss 0.00

    Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure, a low risk of modifcations to data, and limited denial of service.

  • CVE-2021-34394Jun 22, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker to use the malicious CA that is run by the user to cause the buffer overflow, which may lead to information disclosure and data…

  • CVE-2021-34393Jun 22, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.

  • CVE-2021-34392Jun 22, 2021
    risk 0.00cvss epss 0.00

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the tz_map_shared_mem function can bypass boundary checks, which might lead to denial of service.

  • CVE-2021-34391Jun 22, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow through a specific SMC call that is triggered by the user, which may lead to denial of service.

  • CVE-2021-34390Jun 22, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow through a specific SMC call that is triggered by the user, which may lead to denial of service.

  • CVE-2021-34372Jun 22, 2021
    risk 0.00cvss epss 0.00

    Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol message parsing code where an integer overflow in a malloc() size calculation leads to a buffer overflow on the heap, which might result in information…

  • CVE-2021-34389Jun 21, 2021
    risk 0.00cvss epss 0.00

    Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorrect bounds check can allow a local user through a malicious client to access memory from the heap in the TrustZone, which may lead to information disclosure.

  • CVE-2021-34388Jun 21, 2021
    risk 0.00cvss epss 0.00

    Bootloader contains a vulnerability in NVIDIA TegraBoot where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.

Page 17 of 21