Vulnerabilities in nvidia

888 results
Vexday analysis

A NVIDIA apresenta 49 vulnerabilidades catalogadas, das quais 4 são críticas, mas nenhuma está sob ataque ativo no momento. A ausência de publicações nos últimos 90 dias indica um panorama estável, embora a fraqueza dominante seja a desreferência de ponteiro nulo (CWE-476), típica de falhas de validação que podem causar negação de serviço. O risco atual é moderado e não apresenta pressão imediata de exploração em campo.

CVE-2021-34376HIGHTrusty contains a vulnerability in the HDCP service TA where bounds checking in command 5 is missing. Improper restriction of operations witEPSS 0.2%CVE-2026-24248HIGHNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exEPSS 0.2%CVE-2021-1085HIGHNVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to write to a shared memoEPSS 0.2%CVE-2021-1108HIGHNVIDIA Linux kernel distributions contain a vulnerability in FuSa Capture (VI/ISP), where integer underflow due to lack of input validation EPSS 0.2%CVE-2024-53878LOWNVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a maEPSS 0.2%CVE-2025-23358HIGHNVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path element issue. A successfEPSS 0.2%CVE-2022-42260HIGHNVIDIA vGPU Display Driver for Linux guest contains a vulnerability in a D-Bus configuration file, where an unauthorized user in the guest VEPSS 0.2%CVE-2025-23349HIGHNVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a EPSS 0.2%CVE-2025-23354HIGHNVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker mEPSS 0.2%CVE-2025-23353HIGHNVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker mEPSS 0.2%CVE-2021-34379HIGHTrusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an I/O buffer parameterEPSS 0.2%CVE-2023-25514MEDIUMNVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in cuobjdump, where an attacker may cause an out-of-bounds read by trickiEPSS 0.2%CVE-2025-23348HIGHNVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may caEPSS 0.2%CVE-2021-34388MEDIUMBootloader contains a vulnerability in NVIDIA TegraBoot where a potential heap overflow might allow an attacker to control all the RAM afterEPSS 0.2%CVE-2023-25508MEDIUMNVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and EPSS 0.2%CVE-2024-0091HIGHCVEEPSS 0.2%CVE-2021-1120HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be pEPSS 0.2%CVE-2025-23280HIGHNVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerEPSS 0.2%CVE-2023-0191HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds access mayEPSS 0.2%CVE-2023-0183HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an out-of-bounds write can lead to denial of serEPSS 0.2%