CVE-2024-0126
published 2024-10-26CVE-2024-0126: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit…
PriorityP337high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
EPSS
0.34%
25.9th percentile
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) | nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) | nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) | nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla | < nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) | nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) | nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) | nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) | nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-470 | < nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) | nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) |
| debian | nvidia-open-gpu-kernel-modules | < nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) | nvidia-graphics-drivers 535.216.01-1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
osv8.2HIGH
vendor_debian8.2HIGH
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nvidia-display-driver: privilege escalation vulnerability
vendor_redhat·2024-10-26·CVSS 8.2
CVE-2024-0126 [HIGH] CWE-20 nvidia-display-driver: privilege escalation vulnerability
nvidia-display-driver: privilege escalation vulnerability
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
A flaw was found in the NVIDIA GPU Display Driver. A privileged local attacker may be able to exploit this issue to escalate permissions, which can lead to code execution, denial of service, information disclosure, and data tampering.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to w
Debian
CVE-2024-0126: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which c...
vendor_debian·2024·CVSS 8.2
CVE-2024-0126 [HIGH] CVE-2024-0126: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which c...
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Scope: local
bookworm: resolved (fixed in 535.216.01-1~deb12u1)
bullseye: open
forky: resolved (fixed in 535.216.01-1)
sid: resolved (fixed in 535.216.01-1)
trixie: resolved (fixed in 535.216.01-1)
GHSA
GHSA-9gx5-phw8-cmrj: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions
ghsa_unreviewed·2024-10-26
CVE-2024-0126 [HIGH] CWE-20 GHSA-9gx5-phw8-cmrj: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
OSV
CVE-2024-0126: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions
osv·2024-10-26·CVSS 8.2
CVE-2024-0126 [HIGH] CVE-2024-0126: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Suricata
ET WEB_SPECIFIC_APPS SonicWall SMA1000 Directory Traversal Attempt (CVE-2023-0126)
suricata·2024-09-27·CVSS 7.5
CVE-2023-0126 [HIGH] ET WEB_SPECIFIC_APPS SonicWall SMA1000 Directory Traversal Attempt (CVE-2023-0126)
ET WEB_SPECIFIC_APPS SonicWall SMA1000 Directory Traversal Attempt (CVE-2023-0126)
Rule: alert http any any -> $HOME_NET 8443 (msg:"ET WEB_SPECIFIC_APPS SonicWall SMA1000 Directory Traversal Attempt (CVE-2023-0126)"; flow:established,to_server; http.request_line; content:"GET /images/"; fast_pattern; startswith; pcre:"/^.{0,30}(?:(?:\x2e|%2[Ee]){1,2}(?:\x2f|\x5c|%5[Cc]|%2[Ff]){1,}){2,}/R"; reference:url,github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-0126.yaml; reference:cve,2023-0126; classtype:attempted-recon; sid:2056308; rev:2; metadata:affected_product SonicWall, created_at 2024_09_27, cve CVE_2023_0126, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Ne
Suricata
GPL FTP CWD overflow attempt
suricata·2010-09-23
CVE-1999-0219 GPL FTP CWD overflow attempt
GPL FTP CWD overflow attempt
Rule: alert ftp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL FTP CWD overflow attempt"; flow:established,to_server; content:"CWD"; nocase; isdataat:100,relative; pcre:"/^CWD\s[^\n]{100}/smi"; reference:bugtraq,11069; reference:bugtraq,1227; reference:bugtraq,1690; reference:bugtraq,6869; reference:bugtraq,7251; reference:bugtraq,7950; reference:cve,1999-0219; reference:cve,1999-1058; reference:cve,1999-1510; reference:cve,2000-1035; reference:cve,2000-1194; reference:cve,2001-0781; reference:cve,2002-0126; reference:cve,2002-0405; classtype:attempted-admin; sid:2101919; rev:25; metadata:created_at 2010_09_23, cve CVE_1999_0219, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL FTP PASS overflow attempt
suricata·2010-09-23
CVE-1999-1519 GPL FTP PASS overflow attempt
GPL FTP PASS overflow attempt
Rule: alert ftp $EXTERNAL_NET any -> $HOME_NET 21 (msg:"GPL FTP PASS overflow attempt"; flow:established,to_server,no_stream; content:"PASS"; nocase; isdataat:100,relative; pcre:"/^PASS\s[^\n]{100}/smi"; reference:bugtraq,10078; reference:bugtraq,10720; reference:bugtraq,1690; reference:bugtraq,3884; reference:bugtraq,8601; reference:bugtraq,9285; reference:cve,1999-1519; reference:cve,1999-1539; reference:cve,2000-1035; reference:cve,2002-0126; reference:cve,2002-0895; classtype:attempted-admin; sid:2101972; rev:19; metadata:created_at 2010_09_23, cve CVE_1999_1519, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
Suricata
GPL EXPLOIT ISAPI .idq attempt
suricata·2010-09-23
CVE-2000-0071 GPL EXPLOIT ISAPI .idq attempt
GPL EXPLOIT ISAPI .idq attempt
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"GPL EXPLOIT ISAPI .idq attempt"; flow:established,to_server; http.uri; content:".idq?"; nocase; reference:arachnids,553; reference:bugtraq,1065; reference:bugtraq,968; reference:cve,2000-0071; reference:cve,2000-0126; reference:nessus,10115; classtype:web-application-attack; sid:2101244; rev:18; metadata:created_at 2010_09_23, cve CVE_2000_0071, signature_severity Major, updated_at 2024_03_08;)
No public exploits indexed.
No writeups or analysis indexed.
2024-10-26
Published