Nvidia Virtual Gpu vulnerabilities

96 known vulnerabilities affecting nvidia/virtual_gpu.

Total CVEs
96
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH56MEDIUM37LOW2

Vulnerabilities

Page 4 of 5
CVE-2022-42266LOWCVSS 3.3fixed in 11.11≥ 13.0, < 13.6+1 more2022-12-30
CVE-2022-42266 [LOW] CWE-200 CVE-2022-42266: NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sy NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can cause exposure of sensitive information to an actor that is not explicitly authorized to have access to that information, which may lead to limited information disclosure.
nvd
CVE-2022-31617HIGHCVSS 7.8≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-11-19
CVE-2022-31617 [HIGH] CWE-125 CVE-2022-31617: NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sy NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabilities can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.
nvd
CVE-2022-31616HIGHCVSS 7.1≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-11-19
CVE-2022-31616 [HIGH] CWE-20 CVE-2022-31616: NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sy NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to denial of service, or information disclosure.
nvd
CVE-2022-31610HIGHCVSS 7.8≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-11-19
CVE-2022-31610 [HIGH] CWE-787 CVE-2022-31610: NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sy NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where a local user with basic capabilities can cause an out-of-bounds write, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.
nvd
CVE-2022-31612HIGHCVSS 7.1≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-11-19
CVE-2022-31612 [HIGH] CWE-125 CVE-2022-31612: NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sy NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to a system crash or a leak of internal kernel information.
nvd
CVE-2022-31606HIGHCVSS 7.8≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-11-19
CVE-2022-31606 [HIGH] CWE-787 CVE-2022-31606: NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sy NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a failure to properly validate data might allow an attacker with basic user capabilities to cause an out-of-bounds access in kernel mode, which could lead to denial of service, information disclosure, escalation of pr
nvd
CVE-2022-34665MEDIUMCVSS 6.5≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-11-19
CVE-2022-34665 [MEDIUM] CWE-476 CVE-2022-34665: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, w NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service.
nvd
CVE-2022-31613MEDIUMCVSS 6.5≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-11-19
CVE-2022-31613 [MEDIUM] CWE-476 CVE-2022-31613: NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where any l NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where any local user can cause a null-pointer dereference, which may lead to a kernel panic.
nvd
CVE-2022-34666MEDIUMCVSS 5.5fixed in 11.9≥ 13.0, < 13.4+1 more2022-11-10
CVE-2022-34666 [MEDIUM] CWE-476 CVE-2022-34666: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, w NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service.
nvd
CVE-2022-31609HIGHCVSS 7.8≥ 11.0, < 11.8≥ 13.0, < 13.3+2 more2022-08-05
CVE-2022-31609 [HIGH] CWE-285 CVE-2022-31609: NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it all NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and confidentiality, denial of service, or information disclosure.
nvd
CVE-2022-31614HIGHCVSS 7.8≥ 11.0, < 11.8≥ 13.0, < 13.3+2 more2022-08-05
CVE-2022-31614 [HIGH] CWE-415 CVE-2022-31614: NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may exploit this vulnerability with other vulnerabilities to cause denial of service, code execution, and information disclosure.
nvd
CVE-2022-31618MEDIUMCVSS 5.5≥ 11.0, < 11.8≥ 13.0, < 13.3+2 more2022-08-05
CVE-2022-31618 [MEDIUM] CWE-476 CVE-2022-31618: NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a null pointer, which may lead to denial of service.
nvd
CVE-2022-28181CRITICALCVSS 9.9≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-05-17
CVE-2022-28181 [CRITICAL] CWE-787 CVE-2022-28181: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, w NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The scop
nvd
CVE-2022-28183HIGHCVSS 7.1≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-05-17
CVE-2022-28183 [HIGH] CWE-125 CVE-2022-28183: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, w NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user can cause an out-of-bounds read, which may lead to denial of service and information disclosure.
nvd
CVE-2022-28182HIGHCVSS 8.5≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-05-17
CVE-2022-28182 [HIGH] CWE-787 CVE-2022-28182: NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nv NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where an unauthorized attacker on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution to cause denial of service, escalation of privileges, information disclosure, and data tam
nvd
CVE-2022-28184HIGHCVSS 7.8≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-05-17
CVE-2022-28184 [HIGH] CWE-284 CVE-2022-28184: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (n NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering.
nvd
CVE-2022-28185HIGHCVSS 7.1≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-05-17
CVE-2022-28185 [HIGH] CWE-787 CVE-2022-28185: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the ECC layer, where an unprivileged regular user can cause an out-of-bounds write, which may lead to denial of service and data tampering.
nvd
CVE-2022-28188MEDIUMCVSS 5.5≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-05-17
CVE-2022-28188 [MEDIUM] CWE-20 CVE-2022-28188: NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sy NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service.
nvd
CVE-2022-28192MEDIUMCVSS 4.1≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-05-17
CVE-2022-28192 [MEDIUM] CWE-416 CVE-2022-28192: NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may l NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.
nvd
CVE-2022-28186MEDIUMCVSS 6.1≥ 11.0, < 11.8≥ 13.0, < 13.3+1 more2022-05-17
CVE-2022-28186 [MEDIUM] CWE-20 CVE-2022-28186: NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sy NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly, which may lead to denial of service or
nvd