NVIDIA kayıtları
nvidia üreticisine ait 912 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %0,1
- Pre-auth RCE
- 24
- Düzeltme kaydı olan
- %14,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-502 Deserialization of Untrusted Data77
- CWE-20 Improper Input Validation71
- CWE-476 NULL Pointer Dereference63
- CWE-125 Out-of-bounds Read48
- CWE-787 Out-of-bounds Write44
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer43
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
- NVIDIA Public Bug BountyIntigriti · ödüllü · en çok $15.000
- NVIDIA Vulnerability Disclosure ProgramIntigriti · yalnızca bildirim (VDP)
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
912 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2017-14491Kavram kanıtı | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code viathekelleys · dnsmasq · CWE-787 | Kritik9,8 | — | %84,9 | 3 Eki 2017 |
45Planlayın | CVE-2024-0132Kavram kanıtı | NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration nvidia · nvidia container toolkit · CWE-367 | Yüksek8,3 | — | %40,8 | 26 Eyl 2024 |
42Planlayın | CVE-2022-34668Kavram kanıtı | NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivilenvidia · nvflare · CWE-502 | Kritik9,8 | — | %10,9 | 28 Ağu 2022 |
42Planlayın | CVE-2019-5684İstismar yok | NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause nvidia · gpu driver · CWE-787 | Kritik10,0 | — | %5,4 | 6 Ağu 2019 |
41Planlayın | CVE-2024-0087İstismar yok | NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.nvidia · triton inference server · CWE-73 | Yüksek8,8 | — | %19,9 | 14 May 2024 |
41Planlayın | CVE-2019-5685İstismar yok | NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause nvidia · gpu driver · CWE-787 | Kritik9,8 | — | %5,0 | 6 Ağu 2019 |
41Planlayın | CVE-2013-5986İstismar yok | Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 has unknown impact and attack vectors, a different vnvidia · gpu driver | Kritik10,0 | — | %1,8 | 21 Oca 2014 |
41Planlayın | CVE-2015-5053İstismar yok | The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 3nvidia · gpu driver · CWE-284 | Kritik10,0 | — | %1,7 | 24 Kas 2015 |
40Planlayın | CVE-2018-3639Kavram kanıtı | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memintel · atom c · CWE-203 | Orta5,5 | — | %60,6 | 22 May 2018 |
40Planlayın | CVE-2020-11486İstismar yok | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which softwarenvidia · dgx-1 · CWE-434 | Kritik9,8 | — | %2,7 | 29 Eki 2020 |
40Planlayın | CVE-2025-23311İstismar yok | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP requesnvidia · triton inference server · CWE-121 | Kritik9,8 | — | %2,6 | 6 Ağu 2025 |
40Planlayın | CVE-2026-24207Kavram kanıtı | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass.nvidia · triton inference server · CWE-288 | Kritik9,8 | — | %2,6 | 20 May 2026 |
40Planlayın | CVE-2026-65130İstismar yok | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection.nvidia · infra controller · CWE-78 | Kritik9,8 | — | %2,1 | 22 Eyl 2026 |
40Planlayın | CVE-2022-31604İstismar yok | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pinvidia · nvflare · CWE-502 | Kritik9,8 | — | %2,1 | 1 Tem 2022 |
40Planlayın | CVE-2022-31605İstismar yok | NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.nvidia · nvflare · CWE-502 | Kritik9,8 | — | %2,1 | 1 Tem 2022 |
40Planlayın | CVE-2025-23317İstismar yok | NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specinvidia · triton inference server · CWE-122 | Kritik9,8 | — | %2,0 | 6 Ağu 2025 |
40Planlayın | CVE-2025-23242İstismar yok | NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue.nvidia · riva · CWE-284 | Kritik9,8 | — | %1,9 | 11 Mar 2025 |
40Planlayın | CVE-2025-23310İstismar yok | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by specialnvidia · triton inference server · CWE-121 | Kritik9,8 | — | %1,9 | 6 Ağu 2025 |
40Planlayın | CVE-2019-15788İstismar yok | Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.nvidia · clara genomics analysis · CWE-190 | Kritik9,8 | — | %1,8 | 29 Ağu 2019 |
39İzleyin | CVE-2025-23319İstismar yok | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-ofnvidia · triton inference server · CWE-805 | Kritik9,8 | — | %1,6 | 6 Ağu 2025 |
39İzleyin | CVE-2020-11483İstismar yok | NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, containnvidia · dgx-1 · CWE-798 | Kritik9,8 | — | %1,4 | 29 Eki 2020 |
39İzleyin | CVE-2022-28181İstismar yok | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on thenvidia · virtual gpu · CWE-787 | Kritik9,9 | — | %1,1 | 17 May 2022 |
39İzleyin | CVE-2025-23304İstismar yok | NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection nvidia · nemo · CWE-22 | Kritik9,8 | — | %1,1 | 13 Ağu 2025 |
39İzleyin | CVE-2026-24227İstismar yok | NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data.nvidia · tensorrt · CWE-502 | Kritik9,8 | — | %1,0 | 14 Tem 2026 |
39İzleyin | CVE-2026-65098İstismar yok | NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication.nvidia · nemoclaw · CWE-1390 | Kritik9,8 | — | %1,0 | 25 Ağu 2026 |
- CVE-2017-1449164Bu hafta
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via
KritikCVSS 9,8Kavram kanıtıEPSS %85thekelleys · dnsmasq3 Eki 2017
- CVE-2024-013245Planlayın
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration
YüksekCVSS 8,3Kavram kanıtıEPSS %41nvidia · nvidia container toolkit26 Eyl 2024
- CVE-2022-3466842Planlayın
NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivile
KritikCVSS 9,8Kavram kanıtıEPSS %11nvidia · nvflare28 Ağu 2022
- CVE-2019-568442Planlayın
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause
KritikCVSS 10,0İstismar yokEPSS %5nvidia · gpu driver6 Ağu 2019
- CVE-2024-008741Planlayın
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the logging location to an arbitrary file.
YüksekCVSS 8,8İstismar yokEPSS %20nvidia · triton inference server14 May 2024
- CVE-2019-568541Planlayın
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in DirectX drivers, in which a specially crafted shader can cause
KritikCVSS 9,8İstismar yokEPSS %5nvidia · gpu driver6 Ağu 2019
- CVE-2013-598641Planlayın
Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 has unknown impact and attack vectors, a different v
KritikCVSS 10,0İstismar yokEPSS %2nvidia · gpu driver21 Oca 2014
- CVE-2015-505341Planlayın
The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 3
KritikCVSS 10,0İstismar yokEPSS %2nvidia · gpu driver24 Kas 2015
- CVE-2018-363940Planlayın
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior mem
OrtaCVSS 5,5Kavram kanıtıEPSS %61intel · atom c22 May 2018
- CVE-2020-1148640Planlayın
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software
KritikCVSS 9,8İstismar yokEPSS %3nvidia · dgx-129 Eki 2020
- CVE-2025-2331140Planlayın
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially crafted HTTP reques
KritikCVSS 9,8İstismar yokEPSS %3nvidia · triton inference server6 Ağu 2025
- CVE-2026-2420740Planlayın
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass.
KritikCVSS 9,8Kavram kanıtıEPSS %3nvidia · triton inference server20 May 2026
- CVE-2026-6513040Planlayın
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection.
KritikCVSS 9,8İstismar yokEPSS %2nvidia · infra controller22 Eyl 2026
- CVE-2022-3160440Planlayın
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its PKI implementation module, where The CA credentials are transported via pi
KritikCVSS 9,8İstismar yokEPSS %2nvidia · nvflare1 Tem 2022
- CVE-2022-3160540Planlayın
NVFLARE, versions prior to 2.1.2, contains a vulnerability in its utils module, where YAML files are loaded via yaml.load() instead of yaml.
KritikCVSS 9,8İstismar yokEPSS %2nvidia · nvflare1 Tem 2022
- CVE-2025-2331740Planlayın
NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a speci
KritikCVSS 9,8İstismar yokEPSS %2nvidia · triton inference server6 Ağu 2025
- CVE-2025-2324240Planlayın
NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue.
KritikCVSS 9,8İstismar yokEPSS %2nvidia · riva11 Mar 2025
- CVE-2025-2331040Planlayın
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by special
KritikCVSS 9,8İstismar yokEPSS %2nvidia · triton inference server6 Ağu 2025
- CVE-2019-1578840Planlayın
Clara Genomics Analysis before 0.2.0 has an integer overflow for cudapoa memory management in allocate_block.cpp.
KritikCVSS 9,8İstismar yokEPSS %2nvidia · clara genomics analysis29 Ağu 2019
- CVE-2025-2331939İzleyin
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of
KritikCVSS 9,8İstismar yokEPSS %2nvidia · triton inference server6 Ağu 2025
- CVE-2020-1148339İzleyin
NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain
KritikCVSS 9,8İstismar yokEPSS %1nvidia · dgx-129 Eki 2020
- CVE-2022-2818139İzleyin
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the
KritikCVSS 9,9İstismar yokEPSS %1nvidia · virtual gpu17 May 2022
- CVE-2025-2330439İzleyin
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection
KritikCVSS 9,8İstismar yokEPSS %1nvidia · nemo13 Ağu 2025
- CVE-2026-2422739İzleyin
NVIDIA TensorRT for contains a vulnerability where a user might cause a deserialization of untrusted data.
KritikCVSS 9,8İstismar yokEPSS %1nvidia · tensorrt14 Tem 2026
- CVE-2026-6509839İzleyin
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication.
KritikCVSS 9,8İstismar yokEPSS %1nvidia · nemoclaw25 Ağu 2026