CVE-2021-1054
published 2021-01-08CVE-2021-1054: NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.27%
18.4th percentile
NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action, which may lead to denial of service.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | microsoft_edge | — | — |
| nvidia | gpu_driver | >= 390 < 392.63 | 392.63 |
| nvidia | gpu_driver | >= 418 < 427.11 | 427.11 |
| nvidia | gpu_driver | >= 450 < 452.77 | 452.77 |
| nvidia | gpu_driver | >= 460 < 461.09 | 461.09 |
| nvidia | nvidia_gpu_display_driver | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v545-xg3x-8p59: NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm
ghsa_unreviewed·2022-05-24
CVE-2021-1054 [MEDIUM] CWE-863 GHSA-v545-xg3x-8p59: NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm
NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action, which may lead to denial of service.
Microsoft
Chromium: CVE-2021-4059 Insufficient data validation in loader
vendor_msrc·2021-12-14·CVSS 6.5
CVE-2021-4059 [MEDIUM] Chromium: CVE-2021-4059 Insufficient data validation in loader
Chromium: CVE-2021-4059 Insufficient data validation in loader
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the bro
Microsoft
Chromium: CVE-2021-4101 Heap buffer overflow in Swiftshader
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4101 [HIGH] Chromium: CVE-2021-4101 Heap buffer overflow in Swiftshader
Chromium: CVE-2021-4101 Heap buffer overflow in Swiftshader
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.57
12/14/2021
96.0.4664.110
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the brows
Microsoft
Chromium: CVE-2021-4054 Incorrect security UI in autofill
vendor_msrc·2021-12-14·CVSS 6.5
CVE-2021-4054 [MEDIUM] Chromium: CVE-2021-4054 Incorrect security UI in autofill
Chromium: CVE-2021-4054 Incorrect security UI in autofill
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2021-4100 Object lifecycle issue in ANGLE
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4100 [HIGH] Chromium: CVE-2021-4100 Object lifecycle issue in ANGLE
Chromium: CVE-2021-4100 Object lifecycle issue in ANGLE
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.57
12/14/2021
96.0.4664.110
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2021-4052 Use after free in web apps
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4052 [HIGH] Chromium: CVE-2021-4052 Use after free in web apps
Chromium: CVE-2021-4052 Use after free in web apps
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In yo
Microsoft
Chromium: CVE-2021-4062 Heap buffer overflow in BFCache
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4062 [HIGH] Chromium: CVE-2021-4062 Heap buffer overflow in BFCache
Chromium: CVE-2021-4062 Heap buffer overflow in BFCache
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2021-4056: Type Confusion in loader
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4056 [HIGH] Chromium: CVE-2021-4056: Type Confusion in loader
Chromium: CVE-2021-4056: Type Confusion in loader
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In you
Microsoft
Chromium: CVE-2021-4067 Use after free in window manager
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4067 [HIGH] Chromium: CVE-2021-4067 Use after free in window manager
Chromium: CVE-2021-4067 Use after free in window manager
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2021-4063 Use after free in developer tools
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4063 [HIGH] Chromium: CVE-2021-4063 Use after free in developer tools
Chromium: CVE-2021-4063 Use after free in developer tools
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
Microsoft
Chromium: CVE-2021-4066 Integer underflow in ANGLE
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4066 [HIGH] Chromium: CVE-2021-4066 Integer underflow in ANGLE
Chromium: CVE-2021-4066 Integer underflow in ANGLE
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In yo
Microsoft
Chromium: CVE-2021-4098 Insufficient data validation in Mojo
vendor_msrc·2021-12-14·CVSS 7.4
CVE-2021-4098 [HIGH] Chromium: CVE-2021-4098 Insufficient data validation in Mojo
Chromium: CVE-2021-4098 Insufficient data validation in Mojo
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.57
12/14/2021
96.0.4664.110
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the brow
Microsoft
Chromium: CVE-2021-4102 Use after free in V8
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4102 [HIGH] Chromium: CVE-2021-4102 Use after free in V8
Chromium: CVE-2021-4102 Use after free in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware of reports that an exploit for CVE-2021-4102 exists in the wild.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.57
12/14/2021
96.0.4664.110
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-base
Microsoft
Chromium: CVE-2021-4053 Use after free in UI
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4053 [HIGH] Chromium: CVE-2021-4053 Use after free in UI
Chromium: CVE-2021-4053 Use after free in UI
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Mic
Microsoft
Chromium: CVE-2021-4058 Heap buffer overflow in ANGLE
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4058 [HIGH] Chromium: CVE-2021-4058 Heap buffer overflow in ANGLE
Chromium: CVE-2021-4058 Heap buffer overflow in ANGLE
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In
Microsoft
Chromium: CVE-2021-4055 Heap buffer overflow in extensions
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4055 [HIGH] Chromium: CVE-2021-4055 Heap buffer overflow in extensions
Chromium: CVE-2021-4055 Heap buffer overflow in extensions
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser
Microsoft
Chromium: CVE-2021-4057 Use after free in file API
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4057 [HIGH] Chromium: CVE-2021-4057 Use after free in file API
Chromium: CVE-2021-4057 Use after free in file API
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In yo
Microsoft
Chromium: CVE-2021-4099 Use after free in Swiftshader
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4099 [HIGH] Chromium: CVE-2021-4099 Use after free in Swiftshader
Chromium: CVE-2021-4099 Use after free in Swiftshader
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.57
12/14/2021
96.0.4664.110
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
I
Microsoft
Chromium: CVE-2021-4061 Type Confusion in V8
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4061 [HIGH] Chromium: CVE-2021-4061 Type Confusion in V8
Chromium: CVE-2021-4061 Type Confusion in V8
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In your Mic
Microsoft
Chromium: CVE-2021-4068 Insufficient validation of untrusted input in new tab page
vendor_msrc·2021-12-14·CVSS 6.5
CVE-2021-4068 [MEDIUM] Chromium: CVE-2021-4068 Insufficient validation of untrusted input in new tab page
Chromium: CVE-2021-4068 Insufficient validation of untrusted input in new tab page
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see th
Microsoft
Chromium: CVE-2021-4065 Use after free in autofill
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4065 [HIGH] Chromium: CVE-2021-4065 Use after free in autofill
Chromium: CVE-2021-4065 Use after free in autofill
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
In yo
Microsoft
Chromium: CVE-2021-4064 Use after free in screen capture
vendor_msrc·2021-12-14·CVSS 8.8
CVE-2021-4064 [HIGH] Chromium: CVE-2021-4064 Use after free in screen capture
Chromium: CVE-2021-4064 Use after free in screen capture
Description: This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
FAQ: What is the version information for this release?
Microsoft Edge Version
Date Released
Based on Chromium Version
96.0.1054.53
12/10/2021
96.0.4664.93
FAQ: Why is this Chrome CVE included in the Security Update Guide?
The vulnerability assigned to this CVE is in Chromium Open Source Software (OSS) which is consumed by Microsoft Edge (Chromium-based). It is being documented in the Security Update Guide to announce that the latest version of Microsoft Edge (Chromium-based) is no longer vulnerable.
How can I see the version of the browser?
No detection rules found.
Nuclei
Apache Log4j2 - Remote Code Injection
nuclei·CVSS 10.0
CVE-2021-45046 [CRITICAL] Apache Log4j2 - Remote Code Injection
Apache Log4j2 - Remote Code Injection
Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
Template:
id: CVE-2021-45046
info:
name: Apache Log4j2 - Remote Code Injection
author: ImNightmaree
severity: critical
description: Apache Log4j2 Thread Context Lookup Pattern is vulnerable to remote code execution in certain non-default configurations.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
remediation: |
Apply the latest security patches or upgrade to a non-vulnerable version of Apache Log4j2.
reference:
- https://securitylab.github.com/advisories/GHSL-2021-1054_GHSL-2021-1055_log4j2/
- https://twitter.com/marcioalm/status/147174077158165
No writeups or analysis indexed.
2021-01-08
Published