Nvidia Geforce Experience vulnerabilities
36 known vulnerabilities affecting nvidia/geforce_experience.
Total CVEs
36
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH25MEDIUM8LOW2
Vulnerabilities
Page 2 of 2
CVE-2020-5957P4HIGHCVSS 7.8≥ 440, < 442.502020-03-05
CVE-2020-5957 [HIGH] CVE-2020-5957: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Pane
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can corrupt a system file, which may lead to denial of service or escalation of privileges.
nvd
CVE-2017-0316P4HIGHCVSS 7.8≥ 3.0, < 3.10.0.552017-10-16
CVE-2017-0316 [HIGH] CWE-20 CVE-2017-0316: In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerabilit
In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemService64 where a value passed from a user to the driver is used without validation, which may lead to denial of service or possible escalation of privileges.
nvd
CVE-2020-5958P4HIGHCVSS 7.8≥ 440, < 442.502020-03-11
CVE-2020-5958 [HIGH] CVE-2020-5958: NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Pane
NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the NVIDIA Control Panel component in which an attacker with local system access can plant a malicious DLL file, which may lead to code execution, denial of service, or information disclosure.
nvd
CVE-2019-5674P4HIGHCVSS 7.0fixed in 3.182019-03-28
CVE-2019-5674 [HIGH] CWE-59 CVE-2019-5674: NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enab
NVIDIA GeForce Experience before 3.18 contains a vulnerability when ShadowPlay or GameStream is enabled. When an attacker has access to the system and creates a hard link, the software does not check for hard link attacks. This behavior may lead to code execution, denial of service, or escalation of privileges.
nvd
CVE-2021-1072P4HIGHCVSS 7.1fixed in 3.212021-02-05
CVE-2021-1072 [HIGH] CVE-2021-1072: NVIDIA GeForce Experience, all versions prior to 3.21, contains a vulnerability in GameStream (rxdia
NVIDIA GeForce Experience, all versions prior to 3.21, contains a vulnerability in GameStream (rxdiag.dll) where an arbitrary file deletion due to improper handling of log files may lead to denial of service.
nvd
CVE-2018-6261P4HIGHCVSS 7.0fixed in 3.152018-10-02
CVE-2018-6261 [HIGH] CWE-732 CVE-2018-6261: NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled which se
NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled which sets incorrect permissions on a file, which may to code execution, denial of service, or escalation of privileges by users with system access.
nvd
CVE-2018-6257P4HIGHCVSS 7.0≥ 3.0.0, < 3.14.12018-08-31
CVE-2018-6257 [HIGH] CVE-2018-6257: NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameS
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled where improper access control may lead to a denial of service, escalation of privileges, or both.
nvd
CVE-2019-5676P4MEDIUMCVSS 6.7fixed in 3.192019-05-10
CVE-2019-5676 [MEDIUM] CWE-427 CVE-2019-5676: NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in wh
NVIDIA Windows GPU Display driver software for Windows (all versions) contains a vulnerability in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), leading to escalation of privileges through code execution.
nvd
CVE-2021-1079P4MEDIUMCVSS 6.1fixed in 3.222021-04-20
CVE-2021-1079 [MEDIUM] CVE-2021-1079: NVIDIA GeForce Experience, all versions prior to 3.22, contains a vulnerability in GameStream plugin
NVIDIA GeForce Experience, all versions prior to 3.22, contains a vulnerability in GameStream plugins where log files are created using NT/System level permissions, which may lead to code execution, denial of service, or local privilege escalation. The attacker does not have control over the consequence of a modification nor would they be able to leak informa
nvd
CVE-2019-5695P4MEDIUMCVSS 6.5fixed in 3.20.12019-11-12
CVE-2019-5695 [MEDIUM] CWE-427 CVE-2019-5695: NVIDIA GeForce Experience (prior to 3.20.1) and Windows GPU Display Driver (all versions) contains a
NVIDIA GeForce Experience (prior to 3.20.1) and Windows GPU Display Driver (all versions) contains a vulnerability in the local service provider component in which an attacker with local system and privileged access can incorrectly load Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading atta
nvd
CVE-2022-42291P4MEDIUMCVSS 5.5fixed in 3.27.0.112vAll versions prior to 3.27.0.1122023-02-07
CVE-2022-42291 [MEDIUM] CWE-1386 CVE-2022-42291: NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NV
NVIDIA GeForce Experience contains a vulnerability in the installer, where a user installing the NVIDIA GeForce Experience software may inadvertently delete data from a linked location, which may lead to data tampering. An attacker does not have explicit control over the exploitation of this vulnerability, which requires the user to explicitly launc
nvd
CVE-2018-6266P4MEDIUMCVSS 5.5fixed in 3.162018-11-27
CVE-2018-6266 [MEDIUM] CWE-200 CVE-2018-6266: NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a
NVIDIA GeForce Experience contains a vulnerability in all versions prior to 3.16 on Windows where a local user may obtain third party integration parameters, which may lead to information disclosure.
nvd
CVE-2016-4961P4MEDIUMCVSS 5.5≤ -2016-11-08
CVE-2016-4961 [MEDIUM] CWE-20 CVE-2016-4961: For the NVIDIA Quadro, NVS, and GeForce products, improper sanitization of parameters in the NVStrea
For the NVIDIA Quadro, NVS, and GeForce products, improper sanitization of parameters in the NVStreamKMS.sys API layer caused a denial of service vulnerability (blue screen crash) within the NVIDIA Windows graphics drivers.
nvd
CVE-2018-6258P4MEDIUMCVSS 4.7≥ 3.0.0, < 3.14.12018-08-31
CVE-2018-6258 [MEDIUM] CVE-2018-6258: NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability during Gam
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability during GameStream installation where an attacker who has system access can potentially conduct a Man-in-the-Middle (MitM) attack to obtain sensitive information.
nvd
CVE-2018-6262P4LOWCVSS 2.5fixed in 3.152018-10-02
CVE-2018-6262 [LOW] CWE-200 CVE-2018-6262: NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled where li
NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled where limited sensitive user information may be available to users with system access, which may lead to information disclosure.
nvd
CVE-2018-6259P4LOWCVSS 2.5≥ 3.0.0, < 3.14.12018-08-31
CVE-2018-6259 [LOW] CWE-200 CVE-2018-6259: NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameS
NVIDIA GeForce Experience all versions prior to 3.14.1 contains a potential vulnerability when GameStream is enabled, an attacker has system access, and certain system features are enabled, where limited information disclosure may be possible.
nvd
← Previous2 / 2