Vulnerabilities > Nvidia

DATE CVE VULNERABILITY TITLE RISK
2021-07-22 CVE-2021-1091 Link Following vulnerability in Nvidia GPU Display Driver 427.33/452.96/462.31
NVIDIA GPU Display driver for Windows contains a vulnerability where an unprivileged user can create a file hard link that causes the driver to overwrite a file that requires elevated privilege to modify, which could lead to data loss or denial of service.
local
low complexity
nvidia CWE-59
3.6
2021-07-22 CVE-2021-1092 Improper Privilege Management vulnerability in Nvidia GPU Display Driver 427.33/452.96/462.31
NVIDIA GPU Display Driver for Windows contains a vulnerability in the NVIDIA Control Panel application where it is susceptible to a Windows file system symbolic link attack where an unprivileged attacker can cause the applications to overwrite privileged files, resulting in potential denial of service or data loss.
local
low complexity
nvidia CWE-269
3.6
2021-07-22 CVE-2021-1093 Improper Resource Shutdown or Release vulnerability in multiple products
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may lead to denial of service or system crash.
local
low complexity
nvidia debian CWE-404
5.5
2021-07-22 CVE-2021-1094 Out-of-bounds Read vulnerability in multiple products
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure.
local
low complexity
nvidia debian CWE-125
6.1
2021-07-22 CVE-2021-1095 NULL Pointer Dereference vulnerability in multiple products
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service.
local
low complexity
nvidia debian CWE-476
5.5
2021-07-22 CVE-2021-1096 NULL Pointer Dereference vulnerability in Nvidia GPU Display Driver 427.33/452.96/462.31
NVIDIA Windows GPU Display Driver for Windows contains a vulnerability in the NVIDIA kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where dereferencing a NULL pointer may lead to a system crash.
local
low complexity
nvidia CWE-476
4.9
2021-07-21 CVE-2021-1097 Improper Input Validation vulnerability in Nvidia Virtual GPU
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it improperly validates the length field in a request from a guest.
local
low complexity
nvidia CWE-20
4.6
2021-07-21 CVE-2021-1098 Improper Resource Shutdown or Release vulnerability in Nvidia Virtual GPU
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it doesn't release some resources during driver unload requests from guests.
local
low complexity
nvidia CWE-404
4.6
2021-07-21 CVE-2021-1099 Out-of-bounds Write vulnerability in Nvidia Virtual GPU
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) that could allow an attacker to cause stack-based buffer overflow and put a customized ROP gadget on the stack.
local
low complexity
nvidia CWE-787
4.6
2021-07-21 CVE-2021-1100 Unspecified vulnerability in Nvidia Virtual GPU
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel mode driver (nvidia.ko), in which a pointer to a user-space buffer is not validated before it is dereferenced, which may lead to denial of service.
local
low complexity
nvidia
2.1