Vulnerabilities > Nvidia > Geforce Experience > High

DATE CVE VULNERABILITY TITLE RISK
2017-10-16 CVE-2017-0316 Improper Input Validation vulnerability in Nvidia Geforce Experience
In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemService64 where a value passed from a user to the driver is used without validation, which may lead to denial of service or possible escalation of privileges.
local
low complexity
nvidia CWE-20
7.8
2017-04-28 CVE-2017-6250 Unspecified vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience contains a vulnerability in NVIDIA Web Helper.exe, where untrusted script execution may lead to violation of application execution policy and local code execution.
local
low complexity
nvidia
8.8
2016-11-08 CVE-2016-8812 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Nvidia Geforce Experience
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode layer (nvstreamkms.sys) allowing a user to cause a stack buffer overflow with specially crafted executable paths, leading to a denial of service or escalation of privileges.
local
low complexity
nvidia CWE-119
8.8
2016-11-08 CVE-2016-5852 Unspecified vulnerability in Nvidia Geforce Experience
For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows.
local
low complexity
nvidia
7.8
2016-11-08 CVE-2016-4960 Improper Input Validation vulnerability in Nvidia Geforce Experience
For the NVIDIA Quadro, NVS, and GeForce products, the NVIDIA NVStreamKMS.sys service component is improperly validating user-supplied data through its API entry points causing an elevation of privilege.
local
low complexity
nvidia CWE-20
7.3
2016-11-08 CVE-2016-3161 Unspecified vulnerability in Nvidia Geforce Experience
For the NVIDIA Quadro, NVS, and GeForce products, GFE GameStream and NVTray Plugin unquoted service path vulnerabilities are examples of the unquoted service path vulnerability in Windows.
local
low complexity
nvidia
7.8