Vulnerabilities > Nvidia > High

DATE CVE VULNERABILITY TITLE RISK
2020-09-18 CVE-2020-5976 Unspecified vulnerability in Nvidia Games and Geforce NOW
NVIDIA GeForce NOW, versions prior to 2.0.23 (Windows, macOS) and versions prior to 5.31 (Android, Shield TV), contains a vulnerability in the application software where the network test component transmits sensitive information insecurely, which may lead to information disclosure.
network
low complexity
nvidia
7.5
2020-09-18 CVE-2020-5975 Information Exposure vulnerability in Nvidia Geforce NOW
NVIDIA GeForce NOW, versions prior to 2.0.23 on Windows and macOS, contains a vulnerability in the desktop application software that includes sensitive information as part of a URL, which may lead to information disclosure.
network
low complexity
nvidia CWE-200
7.5
2020-07-08 CVE-2020-5974 Incorrect Default Permissions vulnerability in Nvidia Jetpack Software Development KIT 4.2/4.3
NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileges.
local
low complexity
nvidia CWE-276
7.8
2020-06-30 CVE-2020-5972 Release of Invalid Pointer or Reference vulnerability in Nvidia Virtual GPU Manager
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which local pointer variables are not initialized and may be freed later, which may lead to tampering or denial of service.
local
low complexity
nvidia CWE-763
7.1
2020-06-30 CVE-2020-5971 Out-of-bounds Read vulnerability in Nvidia Virtual GPU Manager
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software reads from a buffer by using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer, which may lead to code execution, denial of service, escalation of privileges, or information disclosure.
local
low complexity
nvidia CWE-125
7.8
2020-06-30 CVE-2020-5970 Improper Input Validation vulnerability in Nvidia Virtual GPU Manager
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service.
local
low complexity
nvidia CWE-20
7.1
2020-06-30 CVE-2020-5968 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Nvidia Virtual GPU Manager
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed by using an index or pointer, such as memory or files, which may lead to code execution, denial of service, escalation of privileges, or information disclosure.
local
low complexity
nvidia CWE-119
7.8
2020-06-25 CVE-2020-5966 NULL Pointer Dereference vulnerability in Nvidia GPU Display Driver
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, in which a NULL pointer is dereferenced, leading to denial of service or potential escalation of privileges.
local
low complexity
nvidia CWE-476
7.8
2020-06-25 CVE-2020-5964 Insufficient Verification of Data Authenticity vulnerability in Nvidia products
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the service host component, in which the application resources integrity check may be missed.
local
low complexity
nvidia CWE-345
7.8
2020-06-25 CVE-2020-5963 NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure.
local
low complexity
nvidia canonical
7.8