Vulnerabilities in NVIDIA

742 results
Vexday analysis

O portfólio de vulnerabilidades da NVIDIA reúne 693 CVEs catalogadas, com 18 classificadas como críticas e 58 surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige monitoramento ativo. Nenhuma vulnerabilidade consta atualmente no catálogo KEV da CISA, taxa que fica abaixo da média geral do catálogo, sugerindo menor pressão imediata de exploração em campo — mas não ausência de risco. A CVE mais perigosa no momento é CVE-2024-0132, com EPSS de 0,3646, o valor mais elevado observado no conjunto, o que a posiciona como prioridade de remediação. A falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a afetar componentes de baixo nível como drivers e firmware, onde a superfície de ataque costuma ser ampla e o impacto potencial elevado.

CVE-2021-1080HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), in which certain input data is not validated, which EPSS 0.3%CVE-2021-1083HIGHNVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input lengtEPSS 0.3%CVE-2025-23254HIGHNVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by locaEPSS 0.2%CVE-2021-1075HIGHNVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxEPSS 0.2%CVE-2021-34380HIGHBootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might leaEPSS 0.2%CVE-2023-0180HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in a kernel mode layer handler, which may lead to denial of service or informatEPSS 0.2%CVE-2021-1119HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead tEPSS 0.2%CVE-2025-23361HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause impropeEPSS 0.2%CVE-2022-34684MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an off-by-one error may lead to datEPSS 0.2%CVE-2024-0122HIGHNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker may cause an unauthorized action. EPSS 0.2%CVE-2012-0953MEDIUMKernel heap contents leak race in ioctl handlerEPSS 0.2%CVE-2021-34375HIGHTrusty contains a vulnerability in all trusted applications (TAs) where the stack cookie was not randomized, which might result in stack-basEPSS 0.2%CVE-2022-31607HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where a local user with basic capabilitieEPSS 0.2%CVE-2024-0102LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiEPSS 0.2%CVE-2024-0073HIGHCVEEPSS 0.2%CVE-2022-34679MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unhandled return value can lead to aEPSS 0.2%CVE-2020-11488NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, containEPSS 0.2%CVE-2024-0129MEDIUMNVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extractioEPSS 0.2%CVE-2021-34377HIGHTrusty contains a vulnerability in the HDCP service TA where bounds checking in command 9 is missing. Improper restriction of operations witEPSS 0.2%CVE-2021-34376HIGHTrusty contains a vulnerability in the HDCP service TA where bounds checking in command 5 is missing. Improper restriction of operations witEPSS 0.2%