Vulnerabilidades em NVIDIA

888 resultados
Análise Vexday

O portfólio de vulnerabilidades da NVIDIA reúne 693 CVEs catalogadas, com 18 classificadas como críticas e 58 surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige monitoramento ativo. Nenhuma vulnerabilidade consta atualmente no catálogo KEV da CISA, taxa que fica abaixo da média geral do catálogo, sugerindo menor pressão imediata de exploração em campo — mas não ausência de risco. A CVE mais perigosa no momento é CVE-2024-0132, com EPSS de 0,3646, o valor mais elevado observado no conjunto, o que a posiciona como prioridade de remediação. A falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a afetar componentes de baixo nível como drivers e firmware, onde a superfície de ataque costuma ser ampla e o impacto potencial elevado.

CVE-2026-65082HIGHNVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successfulEPSS 0.2%CVE-2024-0097HIGHCVEEPSS 0.2%CVE-2026-24228HIGHNVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploitEPSS 0.2%CVE-2025-23356HIGHNVIDIA Isaac Lab contains a vulnerability in SB3 configuration parsing. A successful exploit of this vulnerability might lead to code executEPSS 0.2%CVE-2026-24197MEDIUMNVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default iniEPSS 0.2%CVE-2025-23345MEDIUMNVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause an out-of-bounds readEPSS 0.2%CVE-2026-47475MEDIUMNVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a reachable assertion inEPSS 0.2%CVE-2026-47470MEDIUMNVIDIA TensorRT-LLM for any platform contains a vulnerability in the gRPC server chat API endpoint, where an attacker could cause CWE-20 by EPSS 0.2%CVE-2026-24271MEDIUMNVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API, where an attacker could cause allocation of GPU resourcEPSS 0.2%CVE-2025-23285MEDIUMNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resources. A successful eEPSS 0.2%CVE-2025-33190MEDIUMNVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware where an attacker could cause an out-of-bound write. A successful exploit oEPSS 0.2%CVE-2025-23287LOWNVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker may access sensitive system-level information. A successfulEPSS 0.2%CVE-2025-23346LOWNVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereference. A successful exEPSS 0.2%CVE-2025-23248LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-bounds read by passinEPSS 0.2%CVE-2025-23255LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary where a user may cause an out-of-bounds read by passiEPSS 0.2%CVE-2026-47473HIGHNVIDIA TensorRT-LLM contains a vulnerability where an attacker could cause a write-what-where condition. A successful exploit of this vulnerEPSS 0.2%CVE-2026-24226MEDIUMNVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploEPSS 0.2%CVE-2025-23262MEDIUMNVIDIA ConnectX contains a vulnerability in the management interface, where an attacker with local access could cause incorrect authorizatioEPSS 0.2%CVE-2025-33188HIGHNVIDIA DGX Spark GB10 contains a vulnerability in hardware resources where an attacker could tamper with hardware controls. A successful expEPSS 0.2%CVE-2026-24198MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memoryEPSS 0.2%