Vulnerabilities > Nvidia

DATE CVE VULNERABILITY TITLE RISK
2017-05-09 CVE-2017-0347 Improper Validation of Array Index vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed from a user to the driver is not correctly validated and used as the index to an array, which may lead to denial of service or potential escalation of privileges.
local
low complexity
nvidia microsoft CWE-129
7.2
2017-05-09 CVE-2017-0346 Improper Input Validation vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.
local
low complexity
nvidia microsoft CWE-20
7.2
2017-05-09 CVE-2017-0345 Improper Validation of Array Index vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input used as an array size is not correctly validated allows out of bound access in kernel memory and may lead to denial of service or potential escalation of privileges
local
low complexity
nvidia microsoft CWE-129
7.2
2017-05-09 CVE-2017-0344 Local Privilege Escalation vulnerability in NVIDIA GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape may allow users to gain access to arbitrary physical memory, leading to escalation of privileges.
local
low complexity
nvidia microsoft
7.2
2017-05-09 CVE-2017-0343 Race Condition vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) where user can trigger a race condition due to lack of synchronization in two functions leading to a denial of service or potential escalation of privileges.
6.9
2017-05-09 CVE-2017-0342 Incorrect Calculation vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where incorrect calculation may cause an invalid address access leading to denial of service or potential escalation of privileges.
local
low complexity
nvidia microsoft CWE-682
7.2
2017-05-09 CVE-2017-0341 NULL Pointer Dereference vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input can trigger an access to a pointer that has not been initialized which may lead to denial of service or potential escalation of privileges.
local
low complexity
nvidia microsoft CWE-476
7.2
2017-04-28 CVE-2017-6250 Local Code Execution vulnerability in NVIDIA GeForce Experience
NVIDIA GeForce Experience contains a vulnerability in NVIDIA Web Helper.exe, where untrusted script execution may lead to violation of application execution policy and local code execution.
local
low complexity
nvidia
4.6
2017-04-24 CVE-2016-6915 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Nvidia products
Stack-based buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.
local
low complexity
nvidia google CWE-119
7.2
2017-04-24 CVE-2016-6917 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Nvidia products
Buffer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5.
local
low complexity
nvidia google CWE-119
7.2