CVE-2017-0350
published 2017-05-09CVE-2017-0350: All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not…
PriorityP335high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.38%
30.6th percentile
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used in an offset calculation may lead to denial of service or potential escalation of privileges.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 375.66-1 (bookworm) | nvidia-graphics-drivers 375.66-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 375.66-1 (bookworm) | nvidia-graphics-drivers 375.66-1 (bookworm) |
| nvidia_corporation | gpu_display_driver | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
NVIDIA graphics drivers vulnerabilities
vendor_ubuntu·2017-05-31
CVE-2017-0350 NVIDIA graphics drivers vulnerabilities
Title: NVIDIA graphics drivers vulnerabilities
Summary: NVIDIA graphics drivers could be made to crash or run programs as an
administrator.
It was discovered that the NVIDIA graphics drivers contained flaws in the
kernel mode layer. A local attacker could use these issues to cause a denial of
service or potentially escalate their privileges on the system.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2017-0350: nvidia-graphics-drivers - All versions of the NVIDIA GPU Display Driver contain a vulnerability in the ker...
vendor_debian·2017·CVSS 7.8
CVE-2017-0350 [HIGH] CVE-2017-0350: nvidia-graphics-drivers - All versions of the NVIDIA GPU Display Driver contain a vulnerability in the ker...
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used in an offset calculation may lead to denial of service or potential escalation of privileges.
Scope: local
bookworm: resolved (fixed in 375.66-1)
bullseye: resolved (fixed in 375.66-1)
forky: resolved (fixed in 375.66-1)
sid: resolved (fixed in 375.66-1)
trixie: resolved (fixed in 375.66-1)
GHSA
GHSA-qr59-4q3f-jmvp: All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver
ghsa_unreviewed·2022-05-17
CVE-2017-0350 [HIGH] CWE-20 GHSA-qr59-4q3f-jmvp: All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used in an offset calculation may lead to denial of service or potential escalation of privileges.
OSV
CVE-2017-0350: All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver
osv·2017-05-09·CVSS 7.8
CVE-2017-0350 [HIGH] CVE-2017-0350: All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver is not correctly validated and used in an offset calculation may lead to denial of service or potential escalation of privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-05-09
Published