Vulnerabilities > Nvidia

DATE CVE VULNERABILITY TITLE RISK
2022-02-07 CVE-2022-21816 Missing Authentication for Critical Function vulnerability in Nvidia Cloud Gaming Virtual GPU and Virtual GPU
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service.
local
low complexity
nvidia CWE-306
5.5
2022-02-02 CVE-2022-21817 Unspecified vulnerability in Nvidia Omniverse Launcher
NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of privileges, and impact to confidentiality and integrity.
network
low complexity
nvidia
critical
9.3
2022-01-18 CVE-2021-34401 Unspecified vulnerability in Nvidia Shield Experience
NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where improper access control may lead to code execution, compromised integrity, or denial of service.
local
low complexity
nvidia
4.6
2022-01-18 CVE-2021-34402 Out-of-bounds Write vulnerability in Nvidia Shield Experience
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service, Information disclosure, loss of Integrity, or possible escalation of privileges.
local
low complexity
nvidia CWE-787
6.7
2022-01-18 CVE-2021-34403 Use After Free vulnerability in Nvidia Shield Experience
NVIDIA Linux distributions contain a vulnerability in nvmap ioctl, which allows any user with a local account to exploit a use-after-free condition, leading to code privilege escalation, loss of confidentiality and integrity, or denial of service.
local
low complexity
nvidia CWE-416
4.6
2022-01-18 CVE-2021-34404 Unspecified vulnerability in Nvidia Shield Experience
Android images for T210 provided by NVIDIA contain a vulnerability in BROM, where failure to limit access to AHB-DMA when BROM fails may allow an unprivileged attacker with physical access to cause denial of service or impact integrity and confidentiality beyond the security scope of BROM.
local
low complexity
nvidia
4.6
2022-01-18 CVE-2021-34405 Unchecked Return Value vulnerability in Nvidia Shield Experience
NVIDIA Linux distributions contain a vulnerability in TrustZone’s TEE_Malloc function, where an unchecked return value causing a null pointer dereference may lead to denial of service.
local
low complexity
nvidia CWE-252
5.5
2022-01-18 CVE-2021-34406 NULL Pointer Dereference vulnerability in Nvidia Shield Experience
NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointer dereference, which may lead to a system reboot.
local
nvidia CWE-476
4.7
2022-01-10 CVE-2022-22821 Path Traversal vulnerability in Nvidia Nemo
NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available.
local
low complexity
nvidia CWE-22
2.1
2021-12-23 CVE-2021-23175 Incorrect Authorization vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply individual user access controls for users on the same device, which, with user intervention, may lead to escalation of privileges, information disclosure, data tampering, and denial of service, affecting other resources beyond the intended security authority of GameStream.
local
nvidia CWE-863
4.4