Vulnerabilidades em NVIDIA

888 resultados
Análise Vexday

O portfólio de vulnerabilidades da NVIDIA reúne 693 CVEs catalogadas, com 18 classificadas como críticas e 58 surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige monitoramento ativo. Nenhuma vulnerabilidade consta atualmente no catálogo KEV da CISA, taxa que fica abaixo da média geral do catálogo, sugerindo menor pressão imediata de exploração em campo — mas não ausência de risco. A CVE mais perigosa no momento é CVE-2024-0132, com EPSS de 0,3646, o valor mais elevado observado no conjunto, o que a posiciona como prioridade de remediação. A falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a afetar componentes de baixo nível como drivers e firmware, onde a superfície de ataque costuma ser ampla e o impacto potencial elevado.

CVE-2024-0132CRITICALNVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration EPSS 40.8%CVE-2024-0087CRITICALCVEEPSS 19.9%CVE-2024-0088MEDIUMCVEEPSS 18.9%CVE-2022-21820MEDIUMNVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which mayEPSS 16.5%CVE-2022-34668CRITICALNVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileEPSS 10.9%CVE-2026-24208MEDIUMNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vEPSS 5.2%CVE-2019-5684NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause EPSS 4.7%CVE-2019-5685NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause EPSS 4.5%CVE-2025-23359HIGHNVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where aEPSS 3.7%CVE-2025-23266CRITICALNVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could EPSS 3.2%CVE-2026-24168MEDIUMNVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative privileges may causeEPSS 2.8%CVE-2020-11486NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which softwareEPSS 2.7%CVE-2025-23311CRITICALNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP requesEPSS 2.6%CVE-2026-24207CRITICALNVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of thisEPSS 2.6%CVE-2022-28199MEDIUMNVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is nEPSS 2.2%CVE-2022-21821HIGHNVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would requiEPSS 2.1%CVE-2022-31604CRITICALNVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via piEPSS 2.1%CVE-2022-31605CRITICALNVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.EPSS 2.1%CVE-2025-23243MEDIUMNVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability mEPSS 2.1%CVE-2025-23317CRITICALNVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a speciEPSS 2.0%