VYPR

Vendor CVEs

Nvidia

All CVEs

1,157 total · sorted by risk
  • CVE-2025-23286MedAug 2, 2025
    risk 0.29cvss 4.4epss 0.00

    NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2025-23252MedJun 18, 2025
    risk 0.29cvss 4.5epss 0.00

    The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to restricted components. A successful exploit of this vulnerability may lead to information disclosure.

  • CVE-2025-23247MedMay 27, 2025
    risk 0.29cvss 4.4epss 0.00

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a failure to check the length of a buffer could allow a user to cause the tool to crash or execute arbitrary code by passing in a malformed ELF file. A successful exploit of this…

  • CVE-2024-0131MedFeb 2, 2025
    risk 0.29cvss 4.4epss 0.00

    NVIDIA GPU kernel driver for Windows and Linux contains a vulnerability where a potential user-mode attacker could read  a buffer with an incorrect length. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2024-0139MedDec 6, 2024
    risk 0.29cvss 4.4epss 0.00

    NVIDIA Base Command Manager and Bright Cluster Manager for Linux contain an insecure temporary file vulnerability. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2024-0111MedAug 31, 2024
    risk 0.29cvss 4.4epss 0.00

    NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed ELF file. A successful exploit of this vulnerability may lead to a limited denial of service or data tampering.

  • CVE-2024-0110MedAug 31, 2024
    risk 0.29cvss 4.4epss 0.00

    NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by passing in a malformed ELF file. A successful exploit of this vulnerability may lead to code execution or denial of service.

  • CVE-2023-25520MedJun 23, 2023
    risk 0.29cvss 4.4epss 0.00

    NVIDIA Jetson Linux Driver Package contains a vulnerability in nvbootctrl, where a privileged local attacker can configure invalid settings, resulting in denial of service.

  • CVE-2023-0193MedMar 10, 2023
    risk 0.29cvss 4.4epss 0.00

    NVIDIA CUDA Toolkit SDK contains a vulnerability in cuobjdump, where a local user running the tool against a malicious binary may cause an out-of-bounds read, which may result in a limited denial of service and limited information disclosure.

  • CVE-2022-42259MedDec 30, 2022
    risk 0.29cvss 4.4epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow may lead to denial of service.

  • CVE-2022-34673MedDec 30, 2022
    risk 0.29cvss 4.4epss 0.00

    NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering.

  • CVE-2022-34667MedNov 19, 2022
    risk 0.29cvss 4.4epss 0.00

    NVIDIA CUDA Toolkit SDK contains a stack-based buffer overflow vulnerability in cuobjdump, where an unprivileged remote attacker could exploit this buffer overflow condition by persuading a local user to download a specially crafted corrupted file and execute cuobjdump against…

  • CVE-2021-1114MedAug 11, 2021
    risk 0.29cvss 4.4epss 0.00

    NVIDIA Linux kernel distributions contain a vulnerability in the kernel crypto node, where use after free may lead to complete denial of service.

  • CVE-2021-1103MedJul 21, 2021
    risk 0.29cvss 4.4epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a NULL pointer, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).

  • CVE-2021-34392MedJun 22, 2021
    risk 0.29cvss 4.4epss 0.00

    Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the tz_map_shared_mem function can bypass boundary checks, which might lead to denial of service.

  • CVE-2020-5982MedOct 2, 2020
    risk 0.29cvss 4.4epss 0.00

    NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) scheduler, in which the software does not properly limit the number or frequency of interactions that it has with an actor, such as the number of incoming requests,…

  • CVE-2020-5973MedJun 30, 2020
    risk 0.29cvss 4.4epss 0.00

    NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which there is the potential to execute privileged operations, which may lead to denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version…

  • CVE-2019-5698MedNov 9, 2019
    risk 0.29cvss 4.4epss 0.00

    NVIDIA Virtual GPU Manager, all versions, contains a vulnerability in the vGPU plugin, in which an input index value is incorrectly validated, which may lead to denial of service.

  • CVE-2026-24176MedApr 21, 2026
    risk 0.28cvss 4.3epss 0.00

    NVIDIA KAI Scheduler contains a vulnerability where an attacker could cause improper authorization through cross-namespace pod references. A successful exploit of this vulnerability might lead to data tampering.

  • CVE-2026-24241MedFeb 24, 2026
    risk 0.28cvss 4.3epss 0.01

    NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker could exploit an improper authentication issue. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2025-33197MedNov 25, 2025
    risk 0.28cvss 4.3epss 0.00

    NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereference. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-23275MedSep 24, 2025
    risk 0.27cvss 4.2epss 0.00

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GPU out-of-bounds write by providing certain image dimensions. A successful exploit of this vulnerability may lead to denial of service and information…

  • CVE-2025-23302MedSep 4, 2025
    risk 0.27cvss 4.2epss 0.00

    NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the LS10 could enable an attacker to set an unsafe debug access level. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2025-23301MedSep 4, 2025
    risk 0.27cvss 4.2epss 0.00

    NVIDIA HGX and DGX contain a vulnerability where a misconfiguration of the VBIOS could enable an attacker to set an unsafe debug access level. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2024-0134MedNov 5, 2024
    risk 0.27cvss 4.1epss 0.00

    NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful…

  • CVE-2024-0133MedSep 26, 2024
    risk 0.27cvss 4.1epss 0.00

    NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this…

  • CVE-2024-0104MedAug 8, 2024
    risk 0.27cvss 4.2epss 0.00

    NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.

  • CVE-2023-31031MedJan 12, 2024
    risk 0.27cvss 4.2epss 0.00

    NVIDIA DGX Station A100 and DGX Station A800 SBIOS contains a vulnerability where a user may cause a heap-based buffer overflow by local access. A successful exploit of this vulnerability may lead to code execution, denial of service, information disclosure, and data tampering.

  • CVE-2023-31014MedSep 20, 2023
    risk 0.27cvss 4.2epss 0.00

    NVIDIA GeForce Now for Android contains a vulnerability in the game launcher component, where a malicious application on the same device can process the implicit intent meant for the streamer component. A successful exploit of this vulnerability may lead to limited information…

  • CVE-2022-28192MedMay 17, 2022
    risk 0.27cvss 4.1epss 0.00

    NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side…

  • CVE-2021-34400MedNov 20, 2021
    risk 0.27cvss 4.1epss 0.00

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure.

  • CVE-2021-34399MedNov 20, 2021
    risk 0.27cvss 4.1epss 0.00

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure.

  • CVE-2021-23219MedNov 20, 2021
    risk 0.27cvss 4.1epss 0.00

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure.

  • CVE-2021-1125MedNov 20, 2021
    risk 0.27cvss 4.1epss 0.00

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corrupt program data.

  • CVE-2021-1105MedNov 20, 2021
    risk 0.27cvss 4.1epss 0.00

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access debug registers during runtime, which may lead to information disclosure.

  • CVE-2021-1088MedNov 20, 2021
    risk 0.27cvss 4.1epss 0.00

    NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to utilize debug mechanisms with insufficient access control, which may lead to information disclosure.

  • CVE-2021-34394MedJun 22, 2021
    risk 0.27cvss 4.2epss 0.00

    Trusty contains a vulnerability in the NVIDIA OTE protocol that is present in all TAs. An incorrect message stream deserialization allows an attacker to use the malicious CA that is run by the user to cause the buffer overflow, which may lead to information disclosure and data…

  • CVE-2021-34393MedJun 22, 2021
    risk 0.27cvss 4.2epss 0.00

    Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.

  • CVE-2023-25524MedAug 3, 2023
    risk 0.26cvss 4.0epss 0.00

    NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources.…

  • CVE-2021-34395LowJun 22, 2021
    risk 0.25cvss 3.9epss 0.00

    Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure, a low risk of modifcations to data, and limited denial of service.

  • CVE-2025-33199LowNov 25, 2025
    risk 0.21cvss 3.2epss 0.00

    NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow behavior. A successful exploit of this vulnerability might lead to data tampering.

  • CVE-2025-33198LowNov 25, 2025
    risk 0.21cvss 3.3epss 0.00

    NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2025-23346LowSep 24, 2025
    risk 0.21cvss 3.3epss 0.00

    NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereference. A successful exploit of this vulnerability may lead to a limited denial of service.

  • CVE-2025-23340LowSep 24, 2025
    risk 0.21cvss 3.3epss 0.00

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability may lead to a partial denial of service.

  • CVE-2025-23339LowSep 24, 2025
    risk 0.21cvss 3.3epss 0.00

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at…

  • CVE-2025-23338LowSep 24, 2025
    risk 0.21cvss 3.3epss 0.00

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write by running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.

  • CVE-2025-23308LowSep 24, 2025
    risk 0.21cvss 3.3epss 0.00

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to run nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the…

  • CVE-2025-23271LowSep 24, 2025
    risk 0.21cvss 3.3epss 0.00

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability may lead to a partial denial of service.

  • CVE-2025-23255LowSep 24, 2025
    risk 0.21cvss 3.3epss 0.00

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary where a user may cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability may lead to a partial denial of service.

  • CVE-2025-23248LowSep 24, 2025
    risk 0.21cvss 3.3epss 0.00

    NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passing a malformed ELF file to nvdisasm. A successful exploit of this vulnerability may lead to a partial denial of service.

Page 21 of 24