Vulnerabilities in NVIDIA

742 results
Vexday analysis

O portfólio de vulnerabilidades da NVIDIA reúne 693 CVEs catalogadas, com 18 classificadas como críticas e 58 surgidas nos últimos 90 dias, indicando um fluxo contínuo de descobertas que exige monitoramento ativo. Nenhuma vulnerabilidade consta atualmente no catálogo KEV da CISA, taxa que fica abaixo da média geral do catálogo, sugerindo menor pressão imediata de exploração em campo — mas não ausência de risco. A CVE mais perigosa no momento é CVE-2024-0132, com EPSS de 0,3646, o valor mais elevado observado no conjunto, o que a posiciona como prioridade de remediação. A falha mais recorrente é CWE-125 (leitura fora dos limites de buffer), padrão que tende a afetar componentes de baixo nível como drivers e firmware, onde a superfície de ataque costuma ser ampla e o impacto potencial elevado.

CVE-2021-1084HIGHNVIDIA vGPU driver contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input length EPSS 0.3%CVE-2022-34673MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lEPSS 0.3%CVE-2021-34380HIGHBootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might leaEPSS 0.2%CVE-2021-1075HIGHNVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxEPSS 0.2%CVE-2025-23254HIGHNVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by locaEPSS 0.2%CVE-2023-0180HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in a kernel mode layer handler, which may lead to denial of service or informatEPSS 0.2%CVE-2025-23361HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause impropeEPSS 0.2%CVE-2022-34684MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an off-by-one error may lead to datEPSS 0.2%CVE-2021-1119HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead tEPSS 0.2%CVE-2021-34375HIGHTrusty contains a vulnerability in all trusted applications (TAs) where the stack cookie was not randomized, which might result in stack-basEPSS 0.2%CVE-2012-0953MEDIUMKernel heap contents leak race in ioctl handlerEPSS 0.2%CVE-2024-0122HIGHNVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an attacker may cause an unauthorized action. EPSS 0.2%CVE-2024-0102LOWNVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiEPSS 0.2%CVE-2022-31607HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where a local user with basic capabilitieEPSS 0.2%CVE-2024-0073HIGHCVEEPSS 0.2%CVE-2022-34679MEDIUMNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an unhandled return value can lead to aEPSS 0.2%CVE-2020-11488NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, containEPSS 0.2%CVE-2024-0129MEDIUMNVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extractioEPSS 0.2%CVE-2022-28200HIGHNVIDIA DGX A100 contains a vulnerability in SBIOS in the BiosCfgTool, where a local user with elevated privileges can read and write beyond EPSS 0.2%CVE-2022-34678MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause a nuEPSS 0.2%