Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-05-09 CVE-2017-0346 Improper Input Validation vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.
local
low complexity
nvidia CWE-20
7.8
2017-05-09 CVE-2017-0345 Improper Validation of Array Index vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input used as an array size is not correctly validated allows out of bound access in kernel memory and may lead to denial of service or potential escalation of privileges
local
low complexity
nvidia CWE-129
7.8
2017-05-09 CVE-2017-0344 Unspecified vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape may allow users to gain access to arbitrary physical memory, leading to escalation of privileges.
local
low complexity
nvidia
7.8
2017-05-09 CVE-2017-0343 Race Condition vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) where user can trigger a race condition due to lack of synchronization in two functions leading to a denial of service or potential escalation of privileges.
local
high complexity
nvidia CWE-362
7.0
2017-05-09 CVE-2017-0342 Incorrect Calculation vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler where incorrect calculation may cause an invalid address access leading to denial of service or potential escalation of privileges.
local
low complexity
nvidia CWE-682
7.8
2017-05-09 CVE-2017-0341 NULL Pointer Dereference vulnerability in Nvidia GPU Driver
All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where user provided input can trigger an access to a pointer that has not been initialized which may lead to denial of service or potential escalation of privileges.
local
low complexity
nvidia CWE-476
7.8
2017-05-09 CVE-2017-8855 Unspecified vulnerability in Wolfssl
wolfSSL before 3.11.0 does not prevent wc_DhAgree from accepting a malformed DH key.
network
low complexity
wolfssl
7.5
2017-05-09 CVE-2017-8854 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Wolfssl
wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, aka a buffer overflow triggered by a malformed temporary DH file.
local
low complexity
wolfssl CWE-119
7.8
2017-05-09 CVE-2017-8853 Path Traversal vulnerability in Fiyo CMS 2.0.7
Fiyo CMS v2.0.7 has an arbitrary file delete vulnerability in dapur/apps/app_config/controller/backuper.php via directory traversal in the file parameter during an act=db action.
network
low complexity
fiyo CWE-22
7.5
2017-05-09 CVE-2017-3074 Out-of-bounds Write vulnerability in multiple products
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Graphics class.
network
low complexity
adobe redhat CWE-787
8.8