Vulnerabilities > Nvidia > Low

DATE CVE VULNERABILITY TITLE RISK
2018-11-27 CVE-2018-6266 Information Exposure vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtain third party integration parameters, which may lead to information disclosure.
local
low complexity
nvidia microsoft CWE-200
2.1
2018-11-13 CVE-2018-6260 Information Exposure vulnerability in Nvidia GPU Driver
NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters.
local
low complexity
nvidia CWE-200
2.1
2018-10-02 CVE-2018-6262 Information Exposure vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled where limited sensitive user information may be available to users with system access, which may lead to information disclosure.
local
nvidia CWE-200
1.9
2018-08-31 CVE-2018-6258 Unspecified vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability during GameStream installation where an attacker who has system access can potentially conduct a Man-in-the-Middle (MitM) attack to obtain sensitive information.
local
nvidia
1.9
2018-08-31 CVE-2018-6259 Information Exposure vulnerability in Nvidia Geforce Experience
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled, an attacker has system access, and certain system features are enabled, where limited information disclosure may be possible.
local
nvidia CWE-200
1.9
2018-05-22 CVE-2018-3639 Information Exposure Through Discrepancy vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.
2.1
2018-03-06 CVE-2017-6284 Information Exposure vulnerability in multiple products
NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and store or transmits sensitive data using a weakened encryption scheme that is unable to protect sensitive data which may lead to information disclosure.This issue is rated as moderate.
local
low complexity
nvidia google CWE-200
2.1
2018-03-06 CVE-2017-6295 Out-of-bounds Read vulnerability in multiple products
NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or information disclosure.
local
low complexity
nvidia google CWE-125
3.6
2016-11-08 CVE-2016-7386 Information Exposure vulnerability in Nvidia GPU Driver
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000D4 which may lead to leaking of kernel memory contents to user space through an uninitialized buffer.
local
low complexity
nvidia microsoft CWE-200
2.1
2011-01-22 CVE-2011-0636 Information Exposure vulnerability in Nvidia Cuda Toolkit 3.2
The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations.
local
low complexity
nvidia CWE-200
2.1