Vulnerabilidades em Nvidia Corporation

139 resultados
Análise Vexday

Com 138 CVEs catalogadas e nenhuma atualmente listada no CISA KEV, a Nvidia Corporation apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica um perfil de risco relativamente contido em termos de ameaças confirmadas em ambiente real. A ausência de vulnerabilidades de severidade crítica ativas e o fato de nenhuma CVE ter surgido nos últimos 90 dias reforçam um cenário de estabilidade no curto prazo. Ainda assim, duas vulnerabilidades possuem Prova de Conceito (PoC) pública, o que eleva o potencial de tentativas oportunistas de exploração. A CVE mais perigosa identificada atualmente é CVE-2016-8827, com escore EPSS de 0,0532, sugerindo probabilidade baixa, porém não negligenciável, de exploração — recomenda-se verificar se ambientes legados ainda expostos a essa vulnerabilidade foram devidamente corrigidos.

CVE-2016-8827NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOEPSS 5.3%CVE-2017-0332An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code witEPSS 4.1%CVE-2017-0329An elevation of privilege vulnerability in the NVIDIA boot and power management processor driver could enable a local malicious application EPSS 3.9%CVE-2017-0339An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code witEPSS 3.3%CVE-2017-0327An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execute arbitrary code witEPSS 3.2%CVE-2017-0325An elevation of privilege vulnerability in the NVIDIA I2C HID driver could enable a local malicious application to execute arbitrary code wiEPSS 3.2%CVE-2017-0307An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 2.7%CVE-2017-0306An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 2.7%CVE-2017-0338An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 2.7%CVE-2017-0337An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 2.6%CVE-2017-0333An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 2.6%CVE-2017-0335An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code withinEPSS 2.6%CVE-2017-6264An elevation of privilege vulnerability exists in the NVIDIA GPU driver (gm20b_clk_throt_set_cdev_state), where an out of bound memory read EPSS 2.5%CVE-2017-0340An elevation of privilege vulnerability in the NVIDIA Libnvparser component due to a memcpy into a fixed sized buffer with a user-controlledEPSS 2.3%CVE-2018-6242Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attackEPSS 2.3%CVE-2017-0328An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access data outside of itsEPSS 1.6%CVE-2018-6267NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software does not validate or incorrectly validates input that EPSS 1.6%CVE-2018-6268NVIDIA Tegra library contains a vulnerability in libnvmmlite_video.so, where referencing memory after it has been freed may lead to denial oEPSS 1.6%CVE-2017-6247An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code withEPSS 1.5%CVE-2017-6259NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an incorrect detection and recovery from an invaliEPSS 1.3%