Записи NVIDIA
912 опубликованных записей вендора nvidia.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 0,1 %
- Pre-auth RCE
- 24
- С записью об исправлении
- 14,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-502 Deserialization of Untrusted Data77
- CWE-20 Improper Input Validation71
- CWE-476 NULL Pointer Dereference63
- CWE-125 Out-of-bounds Read48
- CWE-787 Out-of-bounds Write44
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer43
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
- NVIDIA Public Bug BountyIntigriti · с вознаграждением · до 15 000 $
- NVIDIA Vulnerability Disclosure ProgramIntigriti · только раскрытие (VDP)
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
912 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2017-14491Proof of concept | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code viathekelleys · dnsmasq · CWE-787 | Критическая9,8 | — | 84,9 % | 3 окт. 2017 г. |
45В плане | CVE-2024-0132Proof of concept | NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration nvidia · nvidia container toolkit · CWE-367 | Высокая8,3 | — | 40,8 % | 26 сент. 2024 г. |
42В плане | CVE-2022-34668Proof of concept | NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivilenvidia · nvflare · CWE-502 | Критическая9,8 | — | 10,9 % | 28 авг. 2022 г. |
42В плане | CVE-2019-5684Эксплойта нет | NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause nvidia · gpu driver · CWE-787 | Критическая10,0 | — | 5,4 % | 6 авг. 2019 г. |
41В плане | CVE-2024-0087Эксплойта нет | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.nvidia · triton inference server · CWE-73 | Высокая8,8 | — | 19,9 % | 14 мая 2024 г. |
41В плане | CVE-2019-5685Эксплойта нет | NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause nvidia · gpu driver · CWE-787 | Критическая9,8 | — | 5,0 % | 6 авг. 2019 г. |
41В плане | CVE-2013-5986Эксплойта нет | Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 has unknown impact and attack vectors, a different vnvidia · gpu driver | Критическая10,0 | — | 1,8 % | 21 янв. 2014 г. |
41В плане | CVE-2015-5053Эксплойта нет | The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 3nvidia · gpu driver · CWE-284 | Критическая10,0 | — | 1,7 % | 24 нояб. 2015 г. |
40В плане | CVE-2018-3639Proof of concept | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Средняя5,5 | — | 60,6 % | 22 мая 2018 г. |
40В плане | CVE-2020-11486Эксплойта нет | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which softwarenvidia · dgx-1 · CWE-434 | Критическая9,8 | — | 2,7 % | 29 окт. 2020 г. |
40В плане | CVE-2025-23311Эксплойта нет | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP requesnvidia · triton inference server · CWE-121 | Критическая9,8 | — | 2,6 % | 6 авг. 2025 г. |
40В плане | CVE-2026-24207Proof of concept | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass.nvidia · triton inference server · CWE-288 | Критическая9,8 | — | 2,6 % | 20 мая 2026 г. |
40В плане | CVE-2026-65130Эксплойта нет | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection.nvidia · infra controller · CWE-78 | Критическая9,8 | — | 2,1 % | 22 сент. 2026 г. |
40В плане | CVE-2022-31604Эксплойта нет | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pinvidia · nvflare · CWE-502 | Критическая9,8 | — | 2,1 % | 1 июл. 2022 г. |
40В плане | CVE-2022-31605Эксплойта нет | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.nvidia · nvflare · CWE-502 | Критическая9,8 | — | 2,1 % | 1 июл. 2022 г. |
40В плане | CVE-2025-23317Эксплойта нет | NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specinvidia · triton inference server · CWE-122 | Критическая9,8 | — | 2,0 % | 6 авг. 2025 г. |
40В плане | CVE-2025-23242Эксплойта нет | NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue.nvidia · riva · CWE-284 | Критическая9,8 | — | 1,9 % | 11 мар. 2025 г. |
40В плане | CVE-2025-23310Эксплойта нет | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by specialnvidia · triton inference server · CWE-121 | Критическая9,8 | — | 1,9 % | 6 авг. 2025 г. |
40В плане | CVE-2019-15788Эксплойта нет | Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.nvidia · clara genomics analysis · CWE-190 | Критическая9,8 | — | 1,8 % | 29 авг. 2019 г. |
39Наблюдать | CVE-2025-23319Эксплойта нет | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-ofnvidia · triton inference server · CWE-805 | Критическая9,8 | — | 1,6 % | 6 авг. 2025 г. |
39Наблюдать | CVE-2020-11483Эксплойта нет | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, containnvidia · dgx-1 · CWE-798 | Критическая9,8 | — | 1,4 % | 29 окт. 2020 г. |
39Наблюдать | CVE-2022-28181Эксплойта нет | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on thenvidia · virtual gpu · CWE-787 | Критическая9,9 | — | 1,1 % | 17 мая 2022 г. |
39Наблюдать | CVE-2025-23304Эксплойта нет | NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection nvidia · nemo · CWE-22 | Критическая9,8 | — | 1,1 % | 13 авг. 2025 г. |
39Наблюдать | CVE-2026-24227Эксплойта нет | NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data.nvidia · tensorrt · CWE-502 | Критическая9,8 | — | 1,0 % | 14 июл. 2026 г. |
39Наблюдать | CVE-2026-65098Эксплойта нет | NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication.nvidia · nemoclaw · CWE-1390 | Критическая9,8 | — | 1,0 % | 25 авг. 2026 г. |
- CVE-2017-1449164На этой неделе
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via
КритическаяCVSS 9,8Proof of conceptEPSS 85 %thekelleys · dnsmasq3 окт. 2017 г.
- CVE-2024-013245В плане
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration
ВысокаяCVSS 8,3Proof of conceptEPSS 41 %nvidia · nvidia container toolkit26 сент. 2024 г.
- CVE-2022-3466842В плане
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivile
КритическаяCVSS 9,8Proof of conceptEPSS 11 %nvidia · nvflare28 авг. 2022 г.
- CVE-2019-568442В плане
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %nvidia · gpu driver6 авг. 2019 г.
- CVE-2024-008741В плане
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.
ВысокаяCVSS 8,8Эксплойта нетEPSS 20 %nvidia · triton inference server14 мая 2024 г.
- CVE-2019-568541В плане
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %nvidia · gpu driver6 авг. 2019 г.
- CVE-2013-598641В плане
Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 has unknown impact and attack vectors, a different v
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %nvidia · gpu driver21 янв. 2014 г.
- CVE-2015-505341В плане
The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 3
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %nvidia · gpu driver24 нояб. 2015 г.
- CVE-2018-363940В плане
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
СредняяCVSS 5,5Proof of conceptEPSS 61 %intel · atom c22 мая 2018 г.
- CVE-2020-1148640В плане
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nvidia · dgx-129 окт. 2020 г.
- CVE-2025-2331140В плане
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP reques
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %nvidia · triton inference server6 авг. 2025 г.
- CVE-2026-2420740В плане
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %nvidia · triton inference server20 мая 2026 г.
- CVE-2026-6513040В плане
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nvidia · infra controller22 сент. 2026 г.
- CVE-2022-3160440В плане
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pi
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nvidia · nvflare1 июл. 2022 г.
- CVE-2022-3160540В плане
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nvidia · nvflare1 июл. 2022 г.
- CVE-2025-2331740В плане
NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a speci
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nvidia · triton inference server6 авг. 2025 г.
- CVE-2025-2324240В плане
NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nvidia · riva11 мар. 2025 г.
- CVE-2025-2331040В плане
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by special
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nvidia · triton inference server6 авг. 2025 г.
- CVE-2019-1578840В плане
Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nvidia · clara genomics analysis29 авг. 2019 г.
- CVE-2025-2331939Наблюдать
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %nvidia · triton inference server6 авг. 2025 г.
- CVE-2020-1148339Наблюдать
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nvidia · dgx-129 окт. 2020 г.
- CVE-2022-2818139Наблюдать
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %nvidia · virtual gpu17 мая 2022 г.
- CVE-2025-2330439Наблюдать
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nvidia · nemo13 авг. 2025 г.
- CVE-2026-2422739Наблюдать
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nvidia · tensorrt14 июл. 2026 г.
- CVE-2026-6509839Наблюдать
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nvidia · nemoclaw25 авг. 2026 г.