Vulnerabilities in nvidia
888 resultsVexday analysis
A NVIDIA apresenta 49 vulnerabilidades catalogadas, das quais 4 são críticas, mas nenhuma está sob ataque ativo no momento. A ausência de publicações nos últimos 90 dias indica um panorama estável, embora a fraqueza dominante seja a desreferência de ponteiro nulo (CWE-476), típica de falhas de validação que podem causar negação de serviço. O risco atual é moderado e não apresenta pressão imediata de exploração em campo.
CVE-2024-0124LOWNVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to readEPSS 0.2%CVE-2025-33217HIGHNVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successful exploit of this vuEPSS 0.2%CVE-2023-25527HIGHNVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an authenticated local attacker may cause corruption of kernel meEPSS 0.2%CVE-2024-0074HIGHCVEEPSS 0.2%CVE-2024-0125LOWNVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dEPSS 0.2%CVE-2024-0111MEDIUMNVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a EPSS 0.2%CVE-2023-0209HIGHNVIDIA DGX-1 SBIOS contains a vulnerability in the Uncore PEI module, where authentication of the code executed by SSA is missing, which mayEPSS 0.2%CVE-2021-1061—NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a preEPSS 0.2%CVE-2026-47626HIGHNVIDIA DGX Spark contains a vulnerability in the system firmware, where a privileged attacker could be able to cause an out-of-bounds write.EPSS 0.2%CVE-2023-25510LOWNVIDIA CUDA Toolkit SDK for Linux and Windows contains a NULL pointer dereference in cuobjdump, where a local user running the tool against EPSS 0.2%CVE-2024-53869MEDIUMNVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A successful exploit of tEPSS 0.2%CVE-2024-0109LOWNVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malformed ELF file. A sucEPSS 0.2%CVE-2025-23340LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passinEPSS 0.2%CVE-2025-23271LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passinEPSS 0.2%CVE-2021-1125MEDIUMNVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to corEPSS 0.2%CVE-2021-34396LOWBootloader contains a vulnerability in access permission settings where unauthorized software may be able to overwrite NVIDIA MB2 code, whicEPSS 0.2%CVE-2024-0080LOW
NVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input validation might enable an attacker to use a specEPSS 0.2%CVE-2026-24193HIGHNVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful explEPSS 0.2%CVE-2023-0182HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of EPSS 0.2%CVE-2022-42275HIGHNVIDIA BMC IPMI handler allows an unauthenticated host to write to a host SPI flash bypassing secureboot protections. This may lead to a losEPSS 0.2%