Vulnerabilities > Nvidia

DATE CVE VULNERABILITY TITLE RISK
2024-09-26 CVE-2024-0132 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Nvidia Container Toolkit and Nvidia GPU Operator
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system.
network
high complexity
nvidia CWE-367
8.3
2024-09-26 CVE-2024-0133 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Nvidia Container Toolkit and Nvidia GPU Operator
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system.
network
high complexity
nvidia CWE-367
3.4
2024-08-31 CVE-2024-0109 Out-of-bounds Read vulnerability in Nvidia Cuda Toolkit
NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malformed ELF file.
local
low complexity
nvidia CWE-125
3.3
2024-08-31 CVE-2024-0110 Out-of-bounds Write vulnerability in Nvidia Cuda Toolkit
NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by passing in a malformed ELF file.
local
low complexity
nvidia CWE-787
7.8
2024-08-31 CVE-2024-0111 Improper Validation of Specified Quantity in Input vulnerability in Nvidia Cuda Toolkit
NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed ELF file.
local
low complexity
nvidia CWE-1284
4.4
2024-08-12 CVE-2024-0113 Path Traversal vulnerability in Nvidia products
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI.
network
low complexity
nvidia CWE-22
8.8
2024-08-12 CVE-2024-0115 Unspecified vulnerability in Nvidia Cv-Cuda
NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue by a long running CV-CUDA Python process.
local
low complexity
nvidia
6.1
2024-08-08 CVE-2024-0104 Unspecified vulnerability in Nvidia products
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access.
network
low complexity
nvidia
8.8
2024-08-08 CVE-2024-0101 Unspecified vulnerability in Nvidia products
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch.
network
low complexity
nvidia
7.5
2024-08-08 CVE-2024-0102 Out-of-bounds Read vulnerability in Nvidia Cuda Toolkit
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiving a user into reading a malformed ELF file.
local
low complexity
nvidia CWE-125
5.5