Vulnerabilidades en NVIDIA

888 resultados
Análisis Vexday

O portfólio de vulnerabilidades da NVIDIA reúne 693 CVEs catalogadas, com 18 classificadas como críticas e 58 surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige monitoramento ativo. Nenhuma vulnerabilidade consta atualmente no catálogo KEV da CISA, taxa que fica abaixo da média geral do catálogo, sugerindo menor pressão imediata de exploração em campo — mas não ausência de risco. A CVE mais perigosa no momento é CVE-2024-0132, com EPSS de 0,3646, o valor mais elevado observado no conjunto, o que a posiciona como prioridade de remediação. A falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a afetar componentes de baixo nível como drivers e firmware, onde a superfície de ataque costuma ser ampla e o impacto potencial elevado.

CVE-2021-34374HIGHTrusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerability can cause memory cEPSS 0.2%CVE-2021-34378HIGHTrusty contains a vulnerability in the HDCP service TA where bounds checking in command 11 is missing. Improper restriction of operations wiEPSS 0.2%CVE-2021-1087MEDIUMNVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), which could allow an attacker to retrieve information EPSS 0.2%CVE-2021-34377HIGHTrusty contains a vulnerability in the HDCP service TA where bounds checking in command 9 is missing. Improper restriction of operations witEPSS 0.2%CVE-2022-34678MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause a nuEPSS 0.2%CVE-2021-1085HIGHNVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where there is the potential to write to a shared memoEPSS 0.2%CVE-2026-24248HIGHNVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exEPSS 0.2%CVE-2021-1108HIGHNVIDIA Linux kernel distributions contain a vulnerability in FuSa Capture (VI/ISP), where integer underflow due to lack of input validation EPSS 0.2%CVE-2024-53878LOWNVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a maEPSS 0.2%CVE-2026-65111HIGHNVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A sEPSS 0.2%CVE-2025-23358HIGHNVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path element issue. A successfEPSS 0.2%CVE-2023-25514MEDIUMNVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in cuobjdump, where an attacker may cause an out-of-bounds read by trickiEPSS 0.2%CVE-2025-23349HIGHNVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a EPSS 0.2%CVE-2025-23354HIGHNVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker mEPSS 0.2%CVE-2022-42260HIGHNVIDIA vGPU Display Driver for Linux guest contains a vulnerability in a D-Bus configuration file, where an unauthorized user in the guest VEPSS 0.2%CVE-2025-23348HIGHNVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may caEPSS 0.2%CVE-2021-34379HIGHTrusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an I/O buffer parameterEPSS 0.2%CVE-2025-23353HIGHNVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker mEPSS 0.2%CVE-2024-0091HIGHCVEEPSS 0.2%CVE-2021-34388MEDIUMBootloader contains a vulnerability in NVIDIA TegraBoot where a potential heap overflow might allow an attacker to control all the RAM afterEPSS 0.2%