Vulnerabilities > Nvidia > Geforce Experience > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-02-07 CVE-2022-42291 Link Following vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering.
local
low complexity
nvidia CWE-59
5.5
2021-04-20 CVE-2021-1079 Unspecified vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience, all versions prior to 3.22, contains a vulnerability in GameStream plugins where log files are created using NT/System level permissions, which may lead to code execution, denial of service, or local privilege escalation.
local
low complexity
nvidia
6.1
2019-11-12 CVE-2019-5695 Uncontrolled Search Path Element vulnerability in Nvidia Geforce Experience and GPU Driver
NVIDIA GeForce Experience (prior to 3.20.1) and Windows GPU Display Driver (all versions) contains a vulnerability in the local service provider component in which an attacker with local system and privileged access can incorrectly load Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), which may lead to denial of service or information disclosure through code execution.
local
low complexity
nvidia CWE-427
6.5
2019-05-10 CVE-2019-5676 Uncontrolled Search Path Element vulnerability in Nvidia Geforce Experience and GPU Display Driver
NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.
local
low complexity
nvidia CWE-427
6.7
2018-11-27 CVE-2018-6266 Information Exposure vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtain third party integration parameters, which may lead to information disclosure.
local
low complexity
nvidia CWE-200
5.5
2018-08-31 CVE-2018-6258 Unspecified vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability during GameStream installation where an attacker who has system access can potentially conduct a Man-in-the-Middle (MitM) attack to obtain sensitive information.
local
high complexity
nvidia
4.7
2016-12-16 CVE-2016-8827 Path Traversal vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience 3.x before GFE 3.1.0.52 contains a vulnerability in NVIDIA Web Helper.exe where a local web API endpoint, /VisualOPS/v.1.0./, lacks proper access control and parameter validation, allowing for information disclosure via a directory traversal attack.
network
low complexity
nvidia CWE-22
6.5
2016-11-08 CVE-2016-4961 Improper Input Validation vulnerability in Nvidia Geforce Experience
For the NVIDIA Quadro, NVS, and GeForce products, improper sanitization of parameters in the NVStreamKMS.sys API layer caused a denial of service vulnerability (blue screen crash) within the NVIDIA Windows graphics drivers.
local
low complexity
nvidia CWE-20
5.5